React security advisory (AV25-804) – Update 1
ID: ee8c5dd9-0a1a-5329-a5b4-82358140b595
STIX ID: report--ee8c5dd9-0a1a-5329-a5b4-82358140b595
Feed Name: Canadian Centre for Cyber Security Alerts and Advisories
On December 3, 2025 the React Foundation published an advisory for CVE-2025-55182 affecting react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack (multiple 19.x versions); the issue has a CVSS score of 10.0, is network-accessible, and PoCs were released. Open-source reporting indicated active exploitation on December 4, 2025 and CISA added the CVE to its Known Exploited Vulnerabilities list on December 5, 2025; the advisory urges immediate mitigation and updates, noting that many frameworks bundling react-server implementations (e.g., Next.js, Vite, Parcel, React Router) may be affected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
