2025-041: Critical Security Vulnerability in React Server Components
ID: 2171548b-1283-5b2f-8c67-93d4227882b4
STIX ID: report--2171548b-1283-5b2f-8c67-93d4227882b4
Feed Name: CERT-EU Security Advisories
**CVE-2025-55182 — Critical RCE in React Server Components:** On December 3, 2025 the React Team disclosed a CVSS 10 vulnerability allowing unauthenticated remote code execution via unsafe deserialization of HTTP payloads sent to React Server Function endpoints; affected packages include react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack and several frameworks (e.g., Next.js App Router); users are advised to update to fixed versions (19.0.1, 19.1.2, or 19.2.1) immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
