Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilitywidely-deployed-product-advisoryopen-source-dependency-vulnerabilityproof-of-concept-release

Critical Unauthenticated RCE Vulnerabilities in React Server Components and Next.js

Updated 3mo agoFirst seen Dec 3, 202569 sources

A critical unauthenticated remote code execution (RCE) vulnerability, tracked as CVE-2025-55182, has been discovered in React Server Components, affecting core React packages (react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack) in versions 19.0, 19.1.0, 19.1.1, and 19.2.0. The flaw arises from unsafe deserialization of payloads sent to React Server Function endpoints, allowing attackers to execute arbitrary code on the server without authentication. This vulnerability also impacts frameworks and bundlers that integrate React Server Components, including Next.js (assigned CVE-2025-66478), Vite, Parcel, React Router, RedwoodSDK, and Waku. Even default configurations and newly generated Next.js applications are vulnerable, and exploitation requires only a crafted HTTP request, with no developer error or special setup needed.

Immediate patching is strongly advised, as the vulnerability is rated CVSS 10.0 (critical) and has been shown to be highly reliable in exploitation tests. Patched versions are available for React (19.0.1, 19.1.2, 19.2.1) and Next.js (15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7), and users are urged to upgrade all affected packages and dependencies. Some hosting providers, such as Vercel, have implemented temporary platform-level mitigations, but these are not a substitute for patching. Security researchers estimate that up to 39% of cloud environments may contain vulnerable instances, underscoring the urgency of remediation across the React and Next.js ecosystem.

Share:
Critical Unauthenticated RCE Vulnerabilities in React Server Components and Next.js
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

12 events from the most recent confirmed update back to the earliest known activity.

12 EVENTS
Dec 16, 20256mo ago

Microsoft details active attacks across Windows and Linux

By 2025-12-16, Microsoft reported active exploitation beginning on 2025-12-05 against both Windows and Linux targets, including reverse shells, Cobalt Strike, RATs, cryptominers, and theft of cloud identity tokens. The report highlighted cross-cloud post-exploitation risk affecting Azure, AWS, and GCP environments.

Dec 12, 20257mo ago

Metasploit adds an exploit module for React2Shell

On 2025-12-12, Rapid7 announced that Metasploit had added an exploit module for CVE-2025-55182, making offensive testing and potential abuse easier for defenders and attackers alike. This followed earlier public PoC and scanner releases.

Dec 11, 20257mo ago

React and Next.js disclose two additional RSC vulnerabilities

On 2025-12-11, React/Next.js disclosed two additional upstream React Server Components issues: CVE-2025-55183, a source code exposure flaw, and CVE-2025-55184, a denial-of-service issue. Next.js stated the original React2Shell patch remained effective against the RCE and released updated fixed versions for the new issues.

Dec 6, 20257mo ago

CISA adds CVE-2025-55182 to the KEV catalog

On 2025-12-06, CISA added CVE-2025-55182 to its Known Exploited Vulnerabilities catalog after active exploitation was confirmed. Federal agencies were given a remediation deadline of 2025-12-26 under BOD 22-01.

Dec 5, 20257mo ago

Kaspersky honeypots record attacks starting December 5

Kaspersky reported that its honeypots began detecting exploitation attempts for CVE-2025-55182 on 2025-12-05, with activity increasing rapidly afterward. The attacks included delivery of botnets, cryptominers, and credential theft tooling.

Post-exploitation campaigns deploy miners, RATs, and remote tools

By early December 2025, observed intrusions were leading to shell access, credential harvesting, Sliver or MeshAgent deployment, cryptomining with XMRig, and other malware activity on compromised servers and containers. Reports also described attempts to steal cloud credentials and establish persistence.

Dec 4, 20257mo ago

Threat actors linked to China begin exploiting React2Shell

Security vendors reported that exploitation activity was attributed in part to China-nexus groups including Earth Lamia and Jackpot Panda, with some reporting additional clusters such as UNC5174. These campaigns targeted exposed applications shortly after disclosure for initial access and follow-on compromise.

Mass scanning and in-the-wild exploitation begin

After public exploit material appeared, researchers observed widespread scanning and active exploitation of internet-facing React and Next.js applications beginning on 2025-12-04. Telemetry and honeypots recorded thousands of attempts against exposed RSC endpoints.

Public exploit code and detection templates appear

By 2025-12-04, public proof-of-concept material and community detection content for CVE-2025-55182 had been released, including Nuclei templates and other exploit-related resources. Multiple reports noted that public exploit availability sharply increased the risk of opportunistic attacks.

Dec 3, 20257mo ago

Hosting and security providers deploy temporary WAF mitigations

Around the public disclosure on 2025-12-03, multiple providers and security vendors rolled out temporary protections such as WAF rules and rapid security rules to help shield exposed React and Next.js deployments. Advisories emphasized these were stopgap measures and not substitutes for patching.

React and Next.js disclose critical RCE and release patches

On 2025-12-03, React publicly disclosed CVE-2025-55182, a CVSS 10.0 unauthenticated RCE in React Server Components, and released fixed React package versions 19.0.1, 19.1.2, and 19.2.1. Next.js simultaneously published its downstream advisory for affected App Router releases and provided patched versions and upgrade guidance.

Lachlan Davidson reports React Server Components flaw via Meta bug bounty

The critical deserialization flaw later assigned CVE-2025-55182 was initially reported to Meta by researcher Lachlan Davidson through Meta’s bug bounty program, starting coordinated validation and remediation work.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

151 LINKEDOpen in app
Affected products
9 linked
Next.JsReactNext.JsReactNodejsReact-NativeKubernetesWakuNode.Js
Organizations
108 linked
VercelAmazon Web ServicesGoogleEarth LamiaJackpot PandaPalo Alto NetworksReactPolySwarmUNC5174UNC5342HiddenOrbitMeta PlatformsWizCloudflareRapid7CISAMicrosoft CorporationWakuViteAmazonAikido SecurityAssetnoteVulnCheckRedwoodSDKParcelArctic WolfCisco SystemsGreyNoiseTenableImpervaSnowflakeQualysVirustotalFastlyFortinetSnykSalt TyphoonCriminal IPWatchTowrEndor LabsUpwindBitdefenderQuad9React FoundationParcel RSCVite RSCAI SPERATrend MicroAkamai TechnologiesSeqriteNginxBeauceron SecurityRondoDoxProjectdiscoveryMiraiCensysSocketSANS InstituteDynatraceFalcoMetasploitStackHawkKasperskyDatadogWordpressFederal Civilian Executive BranchShopifyDependabotCoalitionIndusfaceF5StripeApiiroGitHubAdobeCanadian Centre for Cyber Securitynpm, Inc.Ox SecuritySysdigStepSecurityInfoWorldAppTrana WAAPReact RouterRedwoodJSKing Addons for ElementorReact Core Teamrwsdk@parcel/rscDenoNetlifySuricataNext.js TeamLacework FortiCNAPPFirebase Hosting/App HostingGoogle Cloud ArmorLockBit 4.0InsightVMNextron SystemsMiggo SecurityCobalt StrikeMagento/Adobe CommerceAWS WAFMeshAgentVShellEtherRATXMRigSysdig SecureS-RM
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.