CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2025-55182

🔥 Known Exploited (CISA KEV)CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-12-03
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

Affected Platforms (CPE)

📦
Facebook

React

= 19.0.0= 19.1.0= 19.1.1= 19.2.0
📦
Vercel

Next.js

>= 15.0.0 and < 15.0.5>= 15.1.0 and < 15.1.9>= 15.2.0 and < 15.2.6>= 15.3.0 and < 15.3.6>= 15.4.0 and < 15.4.8>= 15.5.0 and < 15.5.7>= 16.0.0 and < 16.0.7= 14.3.0= 15.6.0= 16.0.0

References & Advisories

相關資安分析文章

相關漏洞威脅