logo

Critical Security Vulnerability in React Server Components (CVE-2025-55182)

ID: e07ad470-1fdb-56a4-934d-a1172031bf44

STIX ID: report--e07ad470-1fdb-56a4-934d-a1172031bf44

Feed Name: Kudelski Security

Threat Score
92/100

Date Published: 2025-12-04

Date Updated: 2026-07-24

...
...

A critical vulnerability (CVE-2025-55182) in React Server Components permits unauthenticated remote code execution by exploiting flawed deserialization of payloads sent to React Server Function endpoints; it affects multiple React (19.0–19.2.0), Next.js (15–16) and numerous frameworks/bundlers, has a CVSS score of 10.0, a public PoC, and requires immediate patching (upgrade to React 19.2.1+ and corresponding framework patches), WAF rules, and enhanced monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.