logo

Critical Vulnerabilities in React and Next.js: everything you need to know

ID: ce91e16a-1dd4-5dc3-8aaa-ecc060ca51bf

STIX ID: report--ce91e16a-1dd4-5dc3-8aaa-ecc060ca51bf

Feed Name: Wiz Blog

Threat Score
93/100

Date Published: 2025-12-03

Date Updated: 2026-05-01

...
...

**CVE-2025-55182 (React)** and **CVE-2025-66478 (Next.js)** are critical unauthenticated RCE vulnerabilities in the React Server Components (RSC) "Flight" protocol that permit remote code execution via insecure deserialization of RSC payloads; default Next.js applications are vulnerable and exploitation requires only a crafted HTTP request. Patched React and Next.js releases are available and immediate patching is strongly recommended, as Wiz reports approximately 39% of cloud environments contain vulnerable instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.