THREAT OPS › Threat News › [NVD] CVE-2025-55182 (CRITICAL 10.0) — A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely
[NVD] CVE-2025-55182 (CRITICAL 10.0) — A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely
CVE-2025-55182 CVSS: 10.0 CRITICAL Published: 2025-12-03T16:15:56.463
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Serv
Indicators of compromise
- CVE-2025-55182cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-55182