peter bassill · operator
$ cve CVE-2025-55182 JSON

CVE-2025-55182 KEV EXPLOIT

10.0
CRITICAL · CVSS 3.1 · EPSS 99.8% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2025-12-12.

Description

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS99.8% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-502
On CISA KEVyes — remediate by 2025-12-12
Public exploityes
Published2025-12-03
Last modified2026-08-04

CISA KEV

NameMeta React Server Components Remote Code Execution Vulnerability
Added2025-12-05
Due2025-12-12
Vendor / productMeta / React Server Components
Ransomware useknown

Affected (2)

VendorProduct
facebookreact
vercelnext.js

Public exploits

SourceTitleDate
exploit-dbReact Server 19.2.0 - Remote Code Execution2026-04-09

References

→ the Explorer  ·  watch your stack  ·  NVD