Critical Vulnerabilities in React Server Components and Next.js
ID: 0ee95cda-a2c5-5703-a9b7-75be1ea3bb4c
STIX ID: report--0ee95cda-a2c5-5703-a9b7-75be1ea3bb4c
Feed Name: Palo Alto Networks Unit 42
On Dec. 3, 2025 Unit 42 disclosed critical RCE vulnerabilities (CVE-2025-55182 and CVE-2025-66478) in the React Server Components Flight protocol affecting React 19 and Next.js (15.x/16.x) and any frameworks bundling the vulnerable react-server packages; the flaws permit unauthenticated, near-100% reliable remote code execution via insecure deserialization and are exploitable in default deployments, prompting immediate patching and providing detection/hunting queries and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
