


Perceptive Security
SOC/SIEM Consultancy

Exploitation of Critical Vulnerability in React Server Components (Updated December 9)
Published:
9 December 2025 at 20:30:55
Alert date:
9 December 2025 at 23:01:20
Source:
unit42.paloaltonetworks.com
Critical CVSS 10.0-rated remote code execution vulnerability in React Server Components Flight protocol, tracked as CVE-2025-55182. The vulnerability affects React Server Components and is being actively discussed by Unit 42 researchers. This represents a maximum severity vulnerability that could allow attackers to execute arbitrary code remotely. The article was updated on December 9, indicating ongoing research or exploitation activity. Also references CVE-2025-66478 related to Next.js framework.
Technical details
Mitigation steps:
Affected products:
React Server Components
Flight Protocol
Next.js
Related links:
https://unit42.paloaltonetworks.com/cve-2025-55182-react-and-cve-2025-66478-next/
https://unit42.paloaltonetworks.com
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
