CVE-2025-55182
CRITICAL CISA KEVDescription
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
CVSS v3.1 Score
CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| react | |
| react | |
| react | |
| react | |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
| vercel | next.js |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-55182? +
How severe is CVE-2025-55182? +
What products are affected by CVE-2025-55182? +
How do I check if I'm vulnerable to CVE-2025-55182? +
Related Vulnerabilities
Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension types …
SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI …
RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configures its Celery workers to accept and deserialize …
A security vulnerability has been identified in the IBL Software Engineering Visual Weather and derived products (NAMIS, Aero Weather, Satellite …
PixelYourSite - Your smart PIXEL (TAG) and API Manager 10.1.1.1 was found to be vulnerable. Unvalidated user input is used …
The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through …