Skip to main content

Critical Security Vulnerability in React Server Components – React

0
Critical
Published: 12/03/2025 (12/03/2025, 16:23:43 UTC)
Source: Reddit NetSec

Description

A critical unauthenticated remote code execution vulnerability (CVE-2025-55182) exists in React Server Components affecting react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack versions 19.0, 19.1.0, 19.1.1, and 19.2.0. The flaw allows attackers to exploit how React decodes payloads sent to Server Function endpoints, potentially executing arbitrary code on the server. A fix was released in versions 19.0.1, 19.1.2, and 19.2.1, and immediate upgrading is strongly recommended. Several popular React frameworks and bundlers are also affected and require updates. Hosting providers have applied temporary mitigations, but these are not a substitute for patching. Additional related vulnerabilities have been disclosed with separate CVEs.

Affected software

Affected versions
>=19.0 <=19.0>=19.1.0 <=19.1.1=19.2.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/20/2026, 03:42:12 UTC

Technical Analysis

React Server Components contain an unauthenticated remote code execution vulnerability (CVE-2025-55182) due to improper deserialization of payloads sent to Server Function endpoints. This vulnerability affects react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack versions 19.0, 19.1.0, 19.1.1, and 19.2.0. An attacker can craft malicious HTTP requests that, when processed by the server, lead to arbitrary code execution. The React team released patched versions 19.0.1, 19.1.2, and 19.2.1 to remediate the issue. Frameworks and bundlers such as next, react-router, waku, @parcel/rsc, @vitejs/plugin-rsc, and rwsdk are also impacted and require updates. Hosting providers have implemented temporary mitigations, but these do not replace the need for immediate upgrades. The vulnerability was responsibly disclosed by Lachlan Davidson and confirmed by Meta security researchers. Additional vulnerabilities related to denial of service and source code exposure have been disclosed with CVEs 2025-55183, 2025-55184, 2025-67779, and 2026-23864.

Potential Impact

This vulnerability allows unauthenticated remote code execution on servers running vulnerable React Server Components packages, potentially leading to full compromise of the server environment. The flaw affects multiple React server-side rendering packages and frameworks that depend on them, increasing the attack surface. Exploitation requires sending crafted HTTP requests to Server Function endpoints. Even applications not explicitly using Server Function endpoints may be vulnerable if they support React Server Components. The severity is critical due to the ease of exploitation and the potential impact on server integrity and confidentiality.

Mitigation Recommendations

A fix is available and has been released in react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack versions 19.0.1, 19.1.2, and 19.2.1. Users should immediately upgrade to these patched versions. Additionally, affected React frameworks and bundlers such as next, react-router, waku, @parcel/rsc, @vitejs/plugin-rsc, and rwsdk should be updated according to the vendor's instructions. Hosting provider mitigations exist but are temporary; do not rely on them as a sole defense. Applications not using React Server Components or Server Function endpoints are not affected. Follow the official React blog and vendor advisories for detailed upgrade instructions and further updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
netsec
Reddit Score
1
Discussion Level
minimal
Content Source
reddit_link_post
Domain
react.dev
Newsworthiness Assessment
{"score":40.1,"reasons":["external_link","newsworthy_keywords:vulnerability","urgent_news_indicators","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["vulnerability"]}
Has External Source
true
Trusted Domain
false

Threat ID: 6930642dca1782a906c02ee5

Added to database: 12/03/2025, 16:24:13 UTC

Last enriched: 08/20/2026, 03:42:12 UTC

Last updated: 09/08/2026, 23:03:11 UTC

Views: 490

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses