THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-55182 (CRITICAL 10.0) — A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely

[NVD] CVE-2025-55182 (CRITICAL 10.0) — A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely

lownvdPublished 2025-12-03

CVE-2025-55182 CVSS: 10.0 CRITICAL Published: 2025-12-03T16:15:56.463

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Serv

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-55182