logo

UPDATE: Critical Security Vulnerability in React Server Components (CVE-2025-55182)

ID: 3d5f1455-c4dc-5859-99a1-cf3aa91d7a92

STIX ID: report--3d5f1455-c4dc-5859-99a1-cf3aa91d7a92

Feed Name: Kudelski Security

Threat Score
90/100

Date Published: 2025-12-04

Date Updated: 2026-07-22

...
...

A critical vulnerability (CVE-2025-55182) in React Server Components enables unauthenticated remote code execution via flawed deserialization of payloads sent to React Server Function endpoints; affected React packages include react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack and multiple React and Next.js versions are listed as vulnerable. The advisory reports a CVSS score of 10.0, notes publicly available proof-of-concept code and trivial exploitation, and urges immediate patching to specified fixed versions, while recommending temporary mitigations such as WAF rules (Cloudflare, Google Cloud Armor, F5, Akamai, Imperva), monitoring for indicators (e.g., payload patterns like "vm#...", "child_process#...", "util#...", "fs#...") and code hardening.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.