CVE-2025-55182

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
MetaCNA
10 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
facebookreact
19.0.0
facebookreact
19.1.0
facebookreact
19.1.1
facebookreact
19.2.0
vercelnext.js
15.0.0 ≤
𝑥
< 15.0.5
vercelnext.js
15.1.0 ≤
𝑥
< 15.1.9
vercelnext.js
15.2.0 ≤
𝑥
< 15.2.6
vercelnext.js
15.3.0 ≤
𝑥
< 15.3.6
vercelnext.js
15.4.0 ≤
𝑥
< 15.4.8
vercelnext.js
15.5.0 ≤
𝑥
< 15.5.7
vercelnext.js
16.0.0 ≤
𝑥
< 16.0.7
vercelnext.js
14.3.0:canary77
vercelnext.js
14.3.0:canary78
vercelnext.js
14.3.0:canary79
vercelnext.js
14.3.0:canary80
vercelnext.js
14.3.0:canary81
vercelnext.js
14.3.0:canary82
vercelnext.js
14.3.0:canary83
vercelnext.js
14.3.0:canary84
vercelnext.js
14.3.0:canary85
vercelnext.js
14.3.0:canary86
vercelnext.js
14.3.0:canary87
vercelnext.js
15.6.0
vercelnext.js
15.6.0:canary0
vercelnext.js
15.6.0:canary1
vercelnext.js
15.6.0:canary10
vercelnext.js
15.6.0:canary11
vercelnext.js
15.6.0:canary12
vercelnext.js
15.6.0:canary13
vercelnext.js
15.6.0:canary14
vercelnext.js
15.6.0:canary15
vercelnext.js
15.6.0:canary16
vercelnext.js
15.6.0:canary17
vercelnext.js
15.6.0:canary18
vercelnext.js
15.6.0:canary19
vercelnext.js
15.6.0:canary2
vercelnext.js
15.6.0:canary20
vercelnext.js
15.6.0:canary21
vercelnext.js
15.6.0:canary22
vercelnext.js
15.6.0:canary23
vercelnext.js
15.6.0:canary24
vercelnext.js
15.6.0:canary25
vercelnext.js
15.6.0:canary26
vercelnext.js
15.6.0:canary27
vercelnext.js
15.6.0:canary28
vercelnext.js
15.6.0:canary29
vercelnext.js
15.6.0:canary3
vercelnext.js
15.6.0:canary30
vercelnext.js
15.6.0:canary31
vercelnext.js
15.6.0:canary32
vercelnext.js
15.6.0:canary33
vercelnext.js
15.6.0:canary34
vercelnext.js
15.6.0:canary35
vercelnext.js
15.6.0:canary36
vercelnext.js
15.6.0:canary37
vercelnext.js
15.6.0:canary38
vercelnext.js
15.6.0:canary39
vercelnext.js
15.6.0:canary4
vercelnext.js
15.6.0:canary40
vercelnext.js
15.6.0:canary41
vercelnext.js
15.6.0:canary42
vercelnext.js
15.6.0:canary43
vercelnext.js
15.6.0:canary44
vercelnext.js
15.6.0:canary45
vercelnext.js
15.6.0:canary46
vercelnext.js
15.6.0:canary47
vercelnext.js
15.6.0:canary48
vercelnext.js
15.6.0:canary49
vercelnext.js
15.6.0:canary5
vercelnext.js
15.6.0:canary50
vercelnext.js
15.6.0:canary51
vercelnext.js
15.6.0:canary52
vercelnext.js
15.6.0:canary53
vercelnext.js
15.6.0:canary54
vercelnext.js
15.6.0:canary55
vercelnext.js
15.6.0:canary56
vercelnext.js
15.6.0:canary57
vercelnext.js
15.6.0:canary6
vercelnext.js
15.6.0:canary7
vercelnext.js
15.6.0:canary8
vercelnext.js
15.6.0:canary9
vercelnext.js
16.0.0
𝑥
= Vulnerable software versions