Skip to main content
EPSS 99.8%top 0.04%

CVE-2025-55182: Deserialization of Untrusted Data (CWE-502) in Meta react-server-dom-webpack

0
Critical
Published: 01/29/2026 (01/29/2026, 00:00:00 UTC)
Source: CVE Database V5
Vendor/Project: Meta
Product: react-server-dom-webpack

Description

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

CVSS v3.1

Score 10.0critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected software

react-server-dom-parcel
pkg:npm/react-server-dom-parcel
Affected versions
=19.0.0=19.1.0=19.1.1=19.2.0
react-server-dom-turbopack
pkg:npm/react-server-dom-turbopack
Affected versions
=19.0.0=19.1.0=19.1.1=19.2.0
react-server-dom-webpack
pkg:npm/react-server-dom-webpack
Affected versions
=19.0.0=19.1.0=19.1.1=19.2.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/04/2026, 13:23:21 UTC

Technical Analysis

This vulnerability (CVE-2025-55182) involves unsafe deserialization (CWE-502) in React Server Components maintained by Meta. Specifically, versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 of react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack unsafely deserialize payloads from HTTP requests directed at Server Function endpoints. This flaw enables unauthenticated remote code execution with complete confidentiality, integrity, and availability impact. The vulnerability is publicly disclosed with a CVSS 3.1 score of 10.0, indicating critical severity. There is no information on available patches or mitigations from the vendor advisory or patch links.

Potential Impact

An unauthenticated attacker can remotely execute arbitrary code on the server running affected versions of React Server Components. This leads to full compromise of confidentiality, integrity, and availability of the affected system. The vulnerability is critical and can be exploited without any user interaction or privileges.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, avoid exposing Server Function endpoints to untrusted networks or inputs. Monitor Meta's official channels for updates and patches addressing this vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
Meta
Date Reserved
2025-08-08T18:21:47.119Z
Cvss Version
3.1
State
PUBLISHED

Indicators of Compromise

Vulnerability

ValueDescriptionCopy
vulnerabilityCVE-2025-55182
vulnerabilityCVE-2025-8088

Domain

ValueDescriptionCopy
domain00857cca77b615c369f48ead5f8eb7f3.com
domain3k7m1n9p4q2r6s8t0v5w2x4y6z8u9.com
domain6b86b273ff34fce1.online
domain8f00b204e9800998.com
domaina7b37115ce3cc2eb.com
domaine4f8c1b9a2d7e3f6c0b5a8d9e2f1c4d.com
domain0aa0cf0637d66c0d.com
domain31d58c226fc5a0aa976e13ca9ecebcc8.com
domain442fe7151fb1e9b5.com
domain7x2k9n4p1q0r5s8t3v6w0y2z4u7b9.com
domain8b21a945159f23b740c836eb50953818.com
domaina8d3b9e1f5c7024d6e0b7a2c9f1d83e5.com
domainaa86a52a98162b7d.com
domainaf4760df2c08896a9638e26e7dd20aae.com
domainb5e9a2d7f4c8e3b1a0d6f2e9c5b8a7d.com
domainbdrv7wlbszfotkqf.uk
domaincfe47df26c8eaf0a7c136b50c703e173.com
domainhexsdk.com
domainpacketsdk.io
domainpacketsdk.net
domainpacketsdk.xyz
domainv46wd6uramzkmeeo.in
domainwillmam.com

Link

ValueDescriptionCopy
linkhttps://otx.alienvault.com/pulse/697ad713f6769b6ddf61162b/
linkhttps://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network
linkhttps://vulnerability.circl.lu/vuln/CVE-2025-8088
linkhttps://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=283&cHash=a64b4a8f662d3639dec8d65f47bc93c5
linkhttps://vulnerability.circl.lu/vuln/CVE-2025-55182
linkhttps://www.facebook.com/security/advisories/cve-2025-55182
linkhttps://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components

Text

ValueDescriptionCopy
textGoogle and partners took action to disrupt the IPIDEA proxy network, believed to be one of the largest residential proxy networks globally. The operation involved legal action to take down control domains, sharing technical intelligence on IPIDEA software development kits, and implementing protections for Android users. IPIDEA's network enabled various malicious activities by routing traffic through residential IP addresses, making it difficult to detect and block. The network was built using SDKs embedded in applications, often without user knowledge. Google's analysis revealed connections between multiple proxy brands and SDKs controlled by the same actors. The disruption aimed to degrade IPIDEA's operations and protect consumers from security risks associated with residential proxies.
textDisrupting the World's Largest Residential Proxy Network
textReport
textThis week Google and partners took action to disrupt what we believe is one of the largest residential proxy networks in the world, the IPIDEA proxy network. IPIDEA’s proxy infrastructure is a little-known component of the digital ecosystem leveraged by a wide array of bad actors.
textNo Place Like Home Network: Disrupting the World's Largest Residential Proxy Network
textBlog
textPUBLISHED

Hash

ValueDescriptionCopy
hash01ac6012d4316b68bb3165ee451f2fcc494e4e37011a73b8cf2680de3364fcf4
hash306184f7c308d95da3bf169d9a615bcf
hashf9060c09cbd328756f01d69b95498713ce1eff04
hashba9b1f4cc2c7f4aeda7a1280bbc901671f4ec3edaa17f1db676e17651e9bff5f
hashb1523d2f5929296a5170a4d6c9db93c8
hash173d2d8935d7df09c9f0e9a3976de3c6ab612106
hashb0726bdd53083968870d0b147b72dad422d6d04f27cd52a7891d038ee83aef5b
hashaef34f14456358db91840c416e55acc7d10185ff2beb362ea24697d7cdad321f
hashfbb784dfe5712c4c0cc82a8b22e7287c
hash0f3aa9431d95f1f823bc341b83b5b3b716faa902
hash59cbdecfc01eba859d12fbeb48f96fe3fe841ac1aafa6bd38eff92f0dcfd4554
hashf252bf30e2635d9fed8fd3f54b2a0ddf
hash01b52f840d67fe9bc9120ba5499b0db99b9fcf6d
hash2d1891b6d0c158ad7280f0f30f3c9d913960a793c6abcda249f9c76e13014e45

Imphash

ValueDescriptionCopy
imphash027ea80e8125c6dda271246922d4c3b0
imphasheb5bc6ff6263b364dfbfb78bdb48ed59
imphashdae02f32a21e03ce65412f6e56942daa

Datetime

ValueDescriptionCopy
datetime2017-08-08T15:54:06+00:00
datetime2020-03-03T07:25:13+00:00
datetime2083-10-10T20:34:47+00:00
datetime2025-08-08T11:11:41.842000+00:00
datetime2025-10-21T22:45:21.069000+00:00
datetime2025-12-03T15:40:56.894000+00:00
datetime2025-12-11T20:15:37.699000+00:00

Size in-bytes

ValueDescriptionCopy
size-in-bytes56358856
size-in-bytes24889336
size-in-bytes75624
size-in-bytes43056480

Threat ID: 69305d3dca1782a906b2331e

Added to database: 12/03/2025, 15:54:37 UTC

Last enriched: 08/04/2026, 13:23:21 UTC

Last updated: 09/10/2026, 19:36:51 UTC

Views: 551

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses