Responding to CVE-2025-55182: Our Experience with the React Server Components Vulnerability
On December 3rd, 2025, the React team disclosed CVE-2025-55182 – a pre-authentication remote code execution vulnerability in React Server Components with a CVSS score of 10.0. Within hours, threat intelligence teams at Amazon, Google, and Microsoft observed active exploitation by multiple actor groups, including state-sponsored operations. The vulnerability affects Next.js, React Router, and essentially any framework implementing React Server Components. This post […]


