logo

How to find Vercel Next.js instances on your network

ID: a1a3ced4-612f-5f53-b172-fd73a0aa305c

STIX ID: report--a1a3ced4-612f-5f53-b172-fd73a0aa305c

Feed Name: runZero Blog

Threat Score
90/100

Date Published: 2025-12-04

Date Updated: 2026-04-29

Author: Matthew Kienow

...
...

**Critical RCE in React/Next.js (CVE-2025-55182):** A remote, unauthenticated code execution vulnerability in React Server Components (affecting react-server-dom-* packages) impacts Next.js App Router applications. The flaw has a CVSS score of 10.0, is being actively exploited, and multiple Next.js versions are listed as vulnerable; users are advised to update to specified patched versions or downgrade experimental canary releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.