Critical Security Vulnerability in React Server Components (CVE-2025-55182)
ID: e07ad470-1fdb-56a4-934d-a1172031bf44
STIX ID: report--e07ad470-1fdb-56a4-934d-a1172031bf44
Feed Name: Kudelski Security
Threat Score
A critical vulnerability (CVE-2025-55182) in React Server Components permits unauthenticated remote code execution by exploiting flawed deserialization of payloads sent to React Server Function endpoints; it affects multiple React (19.0–19.2.0), Next.js (15–16) and numerous frameworks/bundlers, has a CVSS score of 10.0, a public PoC, and requires immediate patching (upgrade to React 19.2.1+ and corresponding framework patches), WAF rules, and enhanced monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
