top of page
perceptive_background_267k.jpg

Critical Vulnerabilities in React Server Components and Next.js

Published:

4 December 2025 at 20:30:55

Alert date:

5 December 2025 at 08:03:23

Source:

unit42.paloaltonetworks.com

Click to open the original link from this advisory

Critical CVSS 10.0-rated remote code execution vulnerabilities discovered in React Server Components Flight protocol. Two CVEs tracked: CVE-2025-55182 and CVE-2025-66478. The vulnerabilities affect React Server Components and Next.js framework implementations. Maximum severity rating indicates potential for complete system compromise. Flight protocol used for server-client communication in React applications is the attack vector.

Technical details

Mitigation steps:

Affected products:

React Server Components
Next.js

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page