CVE-2025-55182
Last modified
CVE-2025-55182 is a critical-severity vulnerability rated 10/10 on the CVSS scale. A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.. CISA has confirmed active exploitation in the wild. EPSS estimates a 99.56% chance of exploitation in the next 30 days.
Description
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| React | 19.0.0 | — | |
| React | 19.1.0 | — | |
| React | 19.1.1 | — | |
| React | 19.2.0 | — | |
| Vercel | Next.Js | >= 15.0.0, < 15.0.5 | — |
| Vercel | Next.Js | >= 15.1.0, < 15.1.9 | — |
| Vercel | Next.Js | >= 15.2.0, < 15.2.6 | — |
| Vercel | Next.Js | >= 15.3.0, < 15.3.6 | — |
| Vercel | Next.Js | >= 15.4.0, < 15.4.8 | — |
| Vercel | Next.Js | >= 15.5.0, < 15.5.7 | — |
| Vercel | Next.Js | >= 16.0.0, < 16.0.7 | — |
| Vercel | Next.Js | 14.3.0 | Canary77 |
| Vercel | Next.Js | 15.6.0 | — |
| Vercel | Next.Js | 16.0.0 | — |
References
- https://www.facebook.com/security/advisories/cve-2025-55182Vendor Advisory
- http://www.openwall.com/lists/oss-security/2025/12/03/4Mailing List, Patch, Third Party Advisory
- https://news.ycombinator.com/item?id=46136026Issue Tracking
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-55182?
How severe is CVE-2025-55182?
How do I fix CVE-2025-55182?
Are you affected by CVE-2025-55182?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
