Skip to content
CC-4723

CC-4723

Digital.Nhs.Uk [email protected] (NHS Digital) December 4, 2025

An attacker could exploit CVE-2025-55182 to perform remote code execution. CVE-2025-55182 affects React and dependent React frameworks such as .js.

An attacker could exploit CVE-2025-55182 to perform remote code execution. CVE-2025-55182 affects React and dependent React frameworks such as .js.

The following platforms are known to be affected:

React Server Components:

If your JavaScript app does not implement any React Server Function endpoints it may still be vulnerable if your app supports React Server Components.

If your app’s React code does not use a server, your app is not affected by this vulnerability. If your app does not use a framework, bundler, or bundler plugin that supports React Server Components, your app is not affected by this vulnerability

The following platforms are also known to be affected:

Some React frameworks and bundlers depend on, have peer dependencies for, or include the vulnerable React packages. The following React frameworks and bundlers are known to be affected:

Web Application Vulnerabilities Often Targeted by Attackers Rapidly After Disclosure

Vulnerabilities in web servers and web application frameworks are often targeted by attackers shortly after vendor disclosure.

The NHS England National CSOC is aware that cyber criminals are attempting to create working exploits for CVE-2025-55182 and assesses that imminent successful exploitation in the wild is highly likely.

React has released a security update to address a critical severity vulnerability in React Server Components. JavaScript applications and frameworks that support React Server Components are also affected. React Server Components allow web application clients to call a function on the React server, translating the HTTP requests into function calls and returning the requested data to the client.

CVE-2025-55182 is an " unauthenticated remote code execution ( RCE )" vulnerability with a CVSS v3 score of 10.0.

A remote, unauthenticated attacker could craft a malicious HTTP request to any Server Function endpoint that, when deserialised by React, could allow the attacker to execute arbitrary code on the server.

Note: CVE-2025-66478 has been issued by Vercel (developers of .js). CVE-2025-66478 is a duplicate of CVE-2025-55182.

Affected organisations must review React's Critical Security Vulnerability in React Server Components advisory and apply the relevant updates as soon as possible.

Required: Patch React Server Components

Affected organisations must update react-server-dom-webpack , react-server-dom-parcel , and react-server-dom-turbopack to a fixed version, which are:

Updating the affected packages can be completed with the following commands:

Required: Patch Frameworks and Applications Using React Server Components

Affected organisations must review their networks for React frameworks and applications that support React Server Components, and update them to the latest fixed version.

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

This CVE is a duplicate of CVE-2025-55182.

Last edited: 4 December 2025 1:43 pm

Extracted Entities