🏷️Topic

Cve-2025-55182

3 articles
First tracked: Dec 4, 2025
Last updated: Jun 21, 2026

Latest Coverage

NextJS Security Vulnerability

↗

Next.js warns of a critical, RSC-related vulnerability (CVE-2025-66478) with CVSS 10 that enables remote code execution in unpatched apps, with explicit fixed versions and upgrade steps across 15.x, 16.x (and certain 14.3.0-canary canaries); no disable switch is available.

Dec 4, 20251%

The React2Shell Story

↗

Security researcher discloses React2Shell RCE in React/Flight (CVE-2025-55182); Meta patched within ~17 hours; millions of sites potentially affected.

May 9, 20261%

Admins and defenders gird themselves against maximum-severity server vuln

↗

A critical remote code execution vulnerability in React Server Components (CVE-2025-55182) can be exploited with a single HTTP request; affects multiple frameworks and is widely used, prompting urgent patching of React and dependencies.

Dec 4, 20251%

Related Entities

🏷️TopicReact
6
🏷️TopicSecurity
93
🏷️TopicNext.js
10
🏷️TopicVercel
17
📈StockRCE
2