CVE-2025-55182: Meta React Server Components Remote Code Execution Vulnerability

Critical severity, CVSS 10.0. Actively exploited: in CISA KEV since 2025-12-05. EPSS: 99.8% chance of exploitation in the next 30 days.

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

Affected products

  • Facebook React: version 19.0.0 only; version 19.1.0 only; version 19.1.1 only; version 19.2.0 only
  • Vercel Next.js: from 15.0.0, before 15.0.5 (fixed in 15.0.5); from 15.1.0, before 15.1.9 (fixed in 15.1.9); from 15.2.0, before 15.2.6 (fixed in 15.2.6); from 15.3.0, before 15.3.6 (fixed in 15.3.6); from 15.4.0, before 15.4.8 (fixed in 15.4.8); from 15.5.0, before 15.5.7 (fixed in 15.5.7); …

Published 2025-12-03. Last modified 2026-10-08.