← Vulnerability feed

Vulnerability record · CVE-2025-55182 · published 3 December 2025

CVE-2025-55182: React Server Components pre-auth deserialization RCE

Facebook · React

React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) unsafely deserialize HTTP request payloads sent to Server Function endpoints. Because the flaw is pre-authentication and network-reachable, any exposed Server Function endpoint can be driven to remote code execution. It affects React and Next.js deployments using these packages.

10.0 CVSS 3.1 Critical CISA KEV since 5 Dec 2025 Known ransomware use EPSS 100% · top 0.1% CWE-502 · Deserialization of untrusted data
10.0CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
6References
4 Aug 2026Last modified by NVD

Description

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 10.0, pre-authentication network RCE, KEV-listed with known ransomware use, and near-certain EPSS probability make this an emergency patch.

What it is

React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) unsafely deserialize HTTP request payloads sent to Server Function endpoints. Because the flaw is pre-authentication and network-reachable, any exposed Server Function endpoint can be driven to remote code execution. It affects React and Next.js deployments using these packages.

Impact

An unauthenticated attacker can execute arbitrary code on the server, leading to full host compromise, data theft, and use of the server as a foothold for lateral movement. CISA KEV lists known ransomware campaign use, so destructive or extortion follow-on is plausible.

Attack surface

Reached over the network via HTTP requests to Server Function endpoints; the CVSS vector shows PR:N and UI:N, so no authentication or user interaction is required. Any internet- or network-exposed React Server Components/Next.js endpoint using the affected packages is in scope.

Exploitation

CISA added it to KEV on 2025-12-05 with a 2025-12-12 due date and flags known ransomware campaign use; EPSS 30-day probability is 0.99802 (99.957th percentile). An AWS advisory reference describes China-nexus groups rapidly exploiting it, indicating active in-the-wild exploitation.

What to do

  • Upgrade React Server Components packages (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) and Next.js to patched versions per the React vendor advisory.
  • If immediate patching is not possible, apply the vendor-recommended mitigations or take affected Server Function endpoints off the network.
  • Restrict network access to Server Function endpoints with authentication, WAF rules, or allowlisting until patched.
  • Follow CISA BOD 22-01 guidance for cloud services and meet the KEV remediation due date.
  • Inventory all React and Next.js deployments to confirm which run the affected 19.0.0, 19.1.0, 19.1.1, or 19.2.0 packages.

Detection

  • Monitor HTTP requests to Server Function endpoints for anomalous or oversized serialized payloads consistent with deserialization abuse.
  • Alert on unexpected child processes, shells, or outbound connections spawned by Node.js/Next.js server processes.
  • Hunt for post-exploitation activity such as web shell drops, credential access, or lateral movement originating from application servers.
  • Review logs for scanning or probing of Server Function routes preceding exploitation attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-55182 to the Known Exploited Vulnerabilities catalog on 5 December 2025 as "Meta React Server Components Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 12 December 2025.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-55182 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2025-29927Next.js middleware authorization bypass via x-middleware-subrequest headerNext.js versions from 1.11.4 up to (but not including) 12.3.5, 13.5.9, 14.2.25, and 15.2.3 allow authorization checks performed in middleware to be b…EPSS 99%analysed8.6CVE-2026-44578Vercel next.js server-side request forgery (ssrf) vulnerabilityNext.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the …EPSS 1.9%8.3CVE-2026-64649Vercel next.js server-side request forgery (ssrf) vulnerabilityNext.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server A…EPSS 0.46%8.3CVE-2026-64642Vercel next.js improper authorization vulnerabilityNext.js is a React framework for building full-stack web applications. In versions 16.0.0 through 16.2.10, crafted requests targeting Next.js applica…EPSS 0.64%8.3CVE-2026-64645Vercel next.js open redirect vulnerabilityNext.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or…EPSS 0.41%8.2CVE-2026-64641Vercel next.js vulnerabilityNext.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, crafted request…EPSS 0.86%8.2CVE-2025-57822Vercel next.js server-side request forgery (ssrf) vulnerabilityNext.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly …EPSS 2.5%8.1CVE-2026-44574Vercel next.js authentication bypass via alternate path vulnerabilityNext.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware…EPSS 0.67%

Source: NIST National Vulnerability Database (record CVE-2025-55182), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.