UPDATE: Critical Security Vulnerability in React Server Components (CVE-2025-55182)
ID: 3d5f1455-c4dc-5859-99a1-cf3aa91d7a92
STIX ID: report--3d5f1455-c4dc-5859-99a1-cf3aa91d7a92
Feed Name: Kudelski Security
A critical vulnerability (CVE-2025-55182) in React Server Components enables unauthenticated remote code execution via flawed deserialization of payloads sent to React Server Function endpoints; affected React packages include react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack and multiple React and Next.js versions are listed as vulnerable. The advisory reports a CVSS score of 10.0, notes publicly available proof-of-concept code and trivial exploitation, and urges immediate patching to specified fixed versions, while recommending temporary mitigations such as WAF rules (Cloudflare, Google Cloud Armor, F5, Akamai, Imperva), monitoring for indicators (e.g., payload patterns like "vm#...", "child_process#...", "util#...", "fs#...") and code hardening.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
