CVE-2025-55182
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
- Published Dec 3, 2025
- CVSS 10.0 critical
- 99.8% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A Metasploit module exploits it
- A fix is available
Affected software
In the news
- The Return of the Kinsing VulnCheck Blog ·
- FortiCloud SSO Login Bypass Vulnerabilities Exploited in the Wild VulnCheck Blog ·
- What's Next: React2Shell Beyond Next.js VulnCheck Blog ·
- React2Shell Exploits on GitHub VulnCheck Blog ·
- React2Shell and What Our Canaries See VulnCheck Blog ·
- Reacting to Shells: React2Shell Variants & the CVE-2025-55182 Exploit Ecosystem VulnCheck Blog ·
- Vulnerability in React Server Components CERT-FR ·
- Critical vulnerability in React and Next.js (CVE-2025-55182) VulnCheck Blog ·