logo

Critical Vulnerabilities in React Server Components and Next.js

ID: 0ee95cda-a2c5-5703-a9b7-75be1ea3bb4c

STIX ID: report--0ee95cda-a2c5-5703-a9b7-75be1ea3bb4c

Feed Name: Palo Alto Networks Unit 42

Threat Score
85/100

Date Published: 2025-12-04

Date Updated: 2026-04-28

Author: Unit 42

...
...

On Dec. 3, 2025 Unit 42 disclosed critical RCE vulnerabilities (CVE-2025-55182 and CVE-2025-66478) in the React Server Components Flight protocol affecting React 19 and Next.js (15.x/16.x) and any frameworks bundling the vulnerable react-server packages; the flaws permit unauthenticated, near-100% reliable remote code execution via insecure deserialization and are exploitable in default deployments, prompting immediate patching and providing detection/hunting queries and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.