







A 10.0 critical severity vulnerablility affecting server-side use of React.js, tracked as CVE-2025-55182 in React.js and CVE-2025-66478 specifically for the Next.js framework.
Critical Security Vulnerability in React Server Components
Discuss @tom.sherman.is's post on Frontpage.
Critical Security Vulnerability in React Server Components – React
The library for web and native user interfaces

GitHub - fatguru/CVE-2025-55182-scanner: A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications
A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications - fatguru/CVE-2025-55182-scanner
High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478) › Searchlight Cyber
This morning, an advisory was released for Next.js about a vulnerability that leads to RCE in default configurations, with no prerequisites. The root cause of this issue lies in React Server Components, which Next.js utilizes. Over the last day, we have noticed an incredible amount of incorrect PoCs floating around on GitHub that do not

Netlify's response to the critical React security vulnerability
Netlify has patched a critical remote code execution vulnerability in React Server Functions. All Netlify customers are protected.

Next.js by Vercel - The React Framework
Production grade React applications that scale. The world's leading companies use Next.js by Vercel to build static and dynamic websites and web applications.

GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blog
A CVSS 8.7 vulnerability in GitHub Enterprise Server allows remote code execution. Read the threat brief and find vulnerable GHES instances from Wiz.

GitHub - assetnote/react2shell-scanner: High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)
High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478) - assetnote/react2shell-scanner
GitHub - lachlan2k/React2Shell-CVE-2025-55182-original-poc: Original Proof-of-Concept's for React2Shell CVE-2025-55182
Original Proof-of-Concept's for React2Shell CVE-2025-55182 - lachlan2k/React2Shell-CVE-2025-55182-original-poc
Railway on Twitter / X
A critical RCE vulnerability was discovered in React Server Components. Railway has collaborated with Meta/Vercel teams & deployed a platform-level patch that blocks malicious requests matching this exploit pattern at our Web Application Firewall.Your service is protected while… https://t.co/8a5WWYshzN— Railway (@Railway) December 3, 2025
How an Omitted Write Barrier in V8 Turns Into RCE in Chrome: CVE-2026-5865
In March, our system detected a severe vulnerability in V8, the JavaScript engine used by Chrome. This vulnerability enabled remote code execution against billions of Chrome users worldwide.

Summary of CVE-2025-55182 - Vercel
Vercel has provided a patch for CVE-2025-55182 affecting any frameworks allowing Server Components usage.
State of React 2025
The 2025 edition of the annual survey about the latest trends in the React ecosystem.

Next.js — The Perpetual Beta Framework
Exploring 6 years of Next.js, from early days to App Router & RSC, with migrations, performance tweaks, and framework insights

Next.js / React Server Components vulnerability identified. Apps deployed on Deno Deploy infrastructure are already protected by a runtime-level patch applied by our team. See this post for more information on how to protect your projects. deno.com/blog/react-server-functions-r…
React Server Functions / Next.js Vulnerability: Deno Deploy users protected | Deno
deno.comThere is critical vulnerability in React Server Components disclosed as CVE-2025-55182 that impacts React 19 and frameworks that use it. A fix has been published in React versions 19.0.1, 19.1.2, and 19.2.1. We recommend upgrading immediately. react.dev/blog/2025/12/03/critical-secu…
Critical Security Vulnerability in React Server Components – React
react.dev