







A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications - fatguru/CVE-2025-55182-scanner
GitHub - assetnote/react2shell-scanner: High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)
High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478) - assetnote/react2shell-scanner
High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478) › Searchlight Cyber
This morning, an advisory was released for Next.js about a vulnerability that leads to RCE in default configurations, with no prerequisites. The root cause of this issue lies in React Server Components, which Next.js utilizes. Over the last day, we have noticed an incredible amount of incorrect PoCs floating around on GitHub that do not

Critical Security Vulnerability in React Server Components – React
The library for web and native user interfaces

Railway on Twitter / X
A critical RCE vulnerability was discovered in React Server Components. Railway has collaborated with Meta/Vercel teams & deployed a platform-level patch that blocks malicious requests matching this exploit pattern at our Web Application Firewall.Your service is protected while… https://t.co/8a5WWYshzN— Railway (@Railway) December 3, 2025
Critical Security Vulnerability in React Server Components
Discuss @tom.sherman.is's post on Frontpage.

State of React 2025
The 2025 edition of the annual survey about the latest trends in the React ecosystem.

codex-security/sdk/typescript/_bundled_plugin/skills/security-scan/references/repository-wide-scan.md at 150d6f6bba5a00d9e3fcccf053fc25b68cee5a57 · openai/codex-security
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security - openai/codex-security
Web Without Walls — Dan Abramov | React Universe Conf 2024
Payload: The Next.js Headless CMS and App Framework
Built with TypeScript and React, Payload is an open-source headless CMS and application framework. Build anything.

Next.js by Vercel - The React Framework
Production grade React applications that scale. The world's leading companies use Next.js by Vercel to build static and dynamic websites and web applications.

next.js/packages/next/README.md at canary · vercel/next.js
The React Framework. Contribute to vercel/next.js development by creating an account on GitHub.
React Server Components: Do They Really Improve Performance?
A data-driven comparison of CSR, SSR, and RSC under the same app and test setup, focusing on initial-load performance and the impact of client- vs server-side data fetching (including Streaming + Suspense).

There is critical vulnerability in React Server Components disclosed as CVE-2025-55182 that impacts React 19 and frameworks that use it. A fix has been published in React versions 19.0.1, 19.1.2, and 19.2.1. We recommend upgrading immediately. react.dev/blog/2025/12/03/critical-secu…
Critical Security Vulnerability in React Server Components – React
react.devNext.js / React Server Components vulnerability identified. Apps deployed on Deno Deploy infrastructure are already protected by a runtime-level patch applied by our team. See this post for more information on how to protect your projects. deno.com/blog/react-server-functions-r…
React Server Functions / Next.js Vulnerability: Deno Deploy users protected | Deno
deno.comI am very proud of the team for the runtime level mitigation we rolled out to @deno_land Deploy for this. It's very precise, very fast, and way less prone to false positives than the WAF based block. All versions of React are safe now when running on Deno Deploy - yay to vertical integration!
React
There is critical vulnerability in React Server Components disclosed as CVE-2025-55182 that impacts React 19 and frameworks that use it. A fix has been published in React versions 19.0.1, 19.1.2, and 19.2.1. We recommend upgrading immediately. react.dev/blog/2025/12/03/critical-secu…