logo

React security advisory (AV25-804) – Update 1

ID: ee8c5dd9-0a1a-5329-a5b4-82358140b595

STIX ID: report--ee8c5dd9-0a1a-5329-a5b4-82358140b595

Feed Name: Canadian Centre for Cyber Security Alerts and Advisories

Threat Score
95/100

Date Published: 2025-12-05

Date Updated: 2026-06-11

Author: Canadian Centre for Cyber Security

...
...

On December 3, 2025 the React Foundation published an advisory for CVE-2025-55182 affecting react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack (multiple 19.x versions); the issue has a CVSS score of 10.0, is network-accessible, and PoCs were released. Open-source reporting indicated active exploitation on December 4, 2025 and CISA added the CVE to its Known Exploited Vulnerabilities list on December 5, 2025; the advisory urges immediate mitigation and updates, noting that many frameworks bundling react-server implementations (e.g., Next.js, Vite, Parcel, React Router) may be affected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.