|
- NVD - CVE-2025-55182
CVE-2025-55182 Detail Description A pre-authentication remote code execution vulnerability exists in React Server Components versions 19 0 0, 19 1 0, 19 1 1, and 19 2 0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack
- Critical React, Next. js flaw lets hackers execute code on servers
A maximum severity vulnerability, dubbed 'React2Shell', in the React Server Components (RSC) 'Flight' protocol allows remote code execution without authentication in React and Next js applications
- React2Shell RCE (CVE-2025-55182) Next. js (CVE-2025-66478) | Tenable®
What is CVE-2025-55182? CVE-2025-55182 is an unsafe deserialization vulnerability in RSC An unauthenticated, remote attacker could exploit this vulnerability by sending a specially crafted payload to a vulnerable React Server Function endpoint Successful exploitation could result in remote code execution on the server
- Critical RCE Vulnerabilities Discovered in React Next. js | Wiz Blog
React and Next js are exposed to critical unauthenticated RCE via CVE-2025-55182 and CVE-2025-66478 Learn which versions are impacted and how to mitigate
- Critical Vulnerabilities in React Server Components and Next. js
CVE-2025-55182 (React) and CVE-2025-66478 (Next js) are classified as Critical (CVSS 10 0) and are caused by insecure deserialization within the RSC architecture, specifically involving the Flight protocol
- React Next. js CVE-2025-55182 66478 RCE: Affected Versions, Exploit . . .
New CVE-2025-55182 and CVE-2025-66478 vulnerabilities expose React Server Components and Next js apps to unauthenticated remote code execution See impacted packages, fixed versions, attack mechanics, and how to quickly confirm real production exposure using Oligo’s runtime visibility
- Security Advisory: CVE-2025-66478 - Next. js
A critical vulnerability (CVE-2025-66478) has been identified in the React Server Components protocol Users should upgrade to patched versions immediately
- CVE-2025-55182: Critical React Exploit Hits Millions of Sites - HackerOne
A critical CVE-2025-55182 React RCE flaw affects millions of sites Get impact details, affected versions, indicators of compromise, and urgent remediation steps
|
|
|