


Perceptive Security
SOC/SIEM Consultancy

Critical Vulnerabilities in React Server Components and Next.js
Published:
4 December 2025 at 20:30:55
Alert date:
5 December 2025 at 08:03:23
Source:
unit42.paloaltonetworks.com

Critical CVSS 10.0-rated remote code execution vulnerabilities discovered in React Server Components Flight protocol. Two CVEs tracked: CVE-2025-55182 and CVE-2025-66478. The vulnerabilities affect React Server Components and Next.js framework implementations. Maximum severity rating indicates potential for complete system compromise. Flight protocol used for server-client communication in React applications is the attack vector.
Technical details
Mitigation steps:
Affected products:
React Server Components
Next.js
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.