Critical Security Vulnerability in React Server Components – React
A critical unauthenticated remote code execution vulnerability (CVE-2025-55182) exists in React Server Components affecting react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack versions 19.0, 19.1.0, 19.1.1, and 19.2.0. The flaw allows attackers to exploit how React decodes payloads sent to Server Function endpoints, potentially executing arbitrary code on the server. A fix was released in versions 19.0.1, 19.1.2, and 19.2.1, and immediate upgrading is strongly recommended. Several popular React frameworks and bundlers are also affected and require updates. Hosting providers have applied temporary mitigations, but these are not a substitute for patching. Additional related vulnerabilities have been disclosed with separate CVEs.
AI Analysis
Technical Summary
React Server Components contain an unauthenticated remote code execution vulnerability (CVE-2025-55182) due to improper deserialization of payloads sent to Server Function endpoints. This vulnerability affects react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack versions 19.0, 19.1.0, 19.1.1, and 19.2.0. An attacker can craft malicious HTTP requests that, when processed by the server, lead to arbitrary code execution. The React team released patched versions 19.0.1, 19.1.2, and 19.2.1 to remediate the issue. Frameworks and bundlers such as next, react-router, waku, @parcel/rsc, @vitejs/plugin-rsc, and rwsdk are also impacted and require updates. Hosting providers have implemented temporary mitigations, but these do not replace the need for immediate upgrades. The vulnerability was responsibly disclosed by Lachlan Davidson and confirmed by Meta security researchers. Additional vulnerabilities related to denial of service and source code exposure have been disclosed with CVEs 2025-55183, 2025-55184, 2025-67779, and 2026-23864.
Potential Impact
This vulnerability allows unauthenticated remote code execution on servers running vulnerable React Server Components packages, potentially leading to full compromise of the server environment. The flaw affects multiple React server-side rendering packages and frameworks that depend on them, increasing the attack surface. Exploitation requires sending crafted HTTP requests to Server Function endpoints. Even applications not explicitly using Server Function endpoints may be vulnerable if they support React Server Components. The severity is critical due to the ease of exploitation and the potential impact on server integrity and confidentiality.
Mitigation Recommendations
A fix is available and has been released in react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack versions 19.0.1, 19.1.2, and 19.2.1. Users should immediately upgrade to these patched versions. Additionally, affected React frameworks and bundlers such as next, react-router, waku, @parcel/rsc, @vitejs/plugin-rsc, and rwsdk should be updated according to the vendor's instructions. Hosting provider mitigations exist but are temporary; do not rely on them as a sole defense. Applications not using React Server Components or Server Function endpoints are not affected. Follow the official React blog and vendor advisories for detailed upgrade instructions and further updates.
Critical Security Vulnerability in React Server Components – React
Description
A critical unauthenticated remote code execution vulnerability (CVE-2025-55182) exists in React Server Components affecting react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack versions 19.0, 19.1.0, 19.1.1, and 19.2.0. The flaw allows attackers to exploit how React decodes payloads sent to Server Function endpoints, potentially executing arbitrary code on the server. A fix was released in versions 19.0.1, 19.1.2, and 19.2.1, and immediate upgrading is strongly recommended. Several popular React frameworks and bundlers are also affected and require updates. Hosting providers have applied temporary mitigations, but these are not a substitute for patching. Additional related vulnerabilities have been disclosed with separate CVEs.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
React Server Components contain an unauthenticated remote code execution vulnerability (CVE-2025-55182) due to improper deserialization of payloads sent to Server Function endpoints. This vulnerability affects react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack versions 19.0, 19.1.0, 19.1.1, and 19.2.0. An attacker can craft malicious HTTP requests that, when processed by the server, lead to arbitrary code execution. The React team released patched versions 19.0.1, 19.1.2, and 19.2.1 to remediate the issue. Frameworks and bundlers such as next, react-router, waku, @parcel/rsc, @vitejs/plugin-rsc, and rwsdk are also impacted and require updates. Hosting providers have implemented temporary mitigations, but these do not replace the need for immediate upgrades. The vulnerability was responsibly disclosed by Lachlan Davidson and confirmed by Meta security researchers. Additional vulnerabilities related to denial of service and source code exposure have been disclosed with CVEs 2025-55183, 2025-55184, 2025-67779, and 2026-23864.
Potential Impact
This vulnerability allows unauthenticated remote code execution on servers running vulnerable React Server Components packages, potentially leading to full compromise of the server environment. The flaw affects multiple React server-side rendering packages and frameworks that depend on them, increasing the attack surface. Exploitation requires sending crafted HTTP requests to Server Function endpoints. Even applications not explicitly using Server Function endpoints may be vulnerable if they support React Server Components. The severity is critical due to the ease of exploitation and the potential impact on server integrity and confidentiality.
Mitigation Recommendations
A fix is available and has been released in react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack versions 19.0.1, 19.1.2, and 19.2.1. Users should immediately upgrade to these patched versions. Additionally, affected React frameworks and bundlers such as next, react-router, waku, @parcel/rsc, @vitejs/plugin-rsc, and rwsdk should be updated according to the vendor's instructions. Hosting provider mitigations exist but are temporary; do not rely on them as a sole defense. Applications not using React Server Components or Server Function endpoints are not affected. Follow the official React blog and vendor advisories for detailed upgrade instructions and further updates.
Technical Details
- Source Type
- Subreddit
- netsec
- Reddit Score
- 1
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Domain
- react.dev
- Newsworthiness Assessment
- {"score":40.1,"reasons":["external_link","newsworthy_keywords:vulnerability","urgent_news_indicators","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["vulnerability"]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6930642dca1782a906c02ee5
Added to database: 12/03/2025, 16:24:13 UTC
Last enriched: 08/20/2026, 03:42:12 UTC
Last updated: 09/08/2026, 23:03:11 UTC
Views: 490
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.