Vulnerability record · CVE-2025-55182 · published 3 December 2025
CVE-2025-55182: React Server Components pre-auth deserialization RCE
Facebook · React
React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) unsafely deserialize HTTP request payloads sent to Server Function endpoints. Because the flaw is pre-authentication and network-reachable, any exposed Server Function endpoint can be driven to remote code execution. It affects React and Next.js deployments using these packages.
Description
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 10.0, pre-authentication network RCE, KEV-listed with known ransomware use, and near-certain EPSS probability make this an emergency patch.
What it is
React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) unsafely deserialize HTTP request payloads sent to Server Function endpoints. Because the flaw is pre-authentication and network-reachable, any exposed Server Function endpoint can be driven to remote code execution. It affects React and Next.js deployments using these packages.
Impact
An unauthenticated attacker can execute arbitrary code on the server, leading to full host compromise, data theft, and use of the server as a foothold for lateral movement. CISA KEV lists known ransomware campaign use, so destructive or extortion follow-on is plausible.
Attack surface
Reached over the network via HTTP requests to Server Function endpoints; the CVSS vector shows PR:N and UI:N, so no authentication or user interaction is required. Any internet- or network-exposed React Server Components/Next.js endpoint using the affected packages is in scope.
Exploitation
CISA added it to KEV on 2025-12-05 with a 2025-12-12 due date and flags known ransomware campaign use; EPSS 30-day probability is 0.99802 (99.957th percentile). An AWS advisory reference describes China-nexus groups rapidly exploiting it, indicating active in-the-wild exploitation.
What to do
- Upgrade React Server Components packages (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) and Next.js to patched versions per the React vendor advisory.
- If immediate patching is not possible, apply the vendor-recommended mitigations or take affected Server Function endpoints off the network.
- Restrict network access to Server Function endpoints with authentication, WAF rules, or allowlisting until patched.
- Follow CISA BOD 22-01 guidance for cloud services and meet the KEV remediation due date.
- Inventory all React and Next.js deployments to confirm which run the affected 19.0.0, 19.1.0, 19.1.1, or 19.2.0 packages.
Detection
- Monitor HTTP requests to Server Function endpoints for anomalous or oversized serialized payloads consistent with deserialization abuse.
- Alert on unexpected child processes, shells, or outbound connections spawned by Node.js/Next.js server processes.
- Hunt for post-exploitation activity such as web shell drops, credential access, or lateral movement originating from application servers.
- Review logs for scanning or probing of Server Function routes preceding exploitation attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-55182 to the Known Exploited Vulnerabilities catalog on 5 December 2025 as "Meta React Server Components Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 12 December 2025.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components | PatchVendor Advisory |
| https://www.facebook.com/security/advisories/cve-2025-55182 | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/12/03/4 | Mailing ListPatchThird Party Advisory |
| https://news.ycombinator.com/item?id=46136026 | Issue Tracking |
| https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025 | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182 | US Government Resource |
Track CVE-2025-55182 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-55182), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.