← Back to Resources
Open Source NewsDecember 3, 20252 min read

Critical Security Vulnerability Disclosed in React Server Components

By BIOS Founding Team

Critical Security Vulnerability Disclosed in React Server Components

The React team disclosed CVE-2025-55182, a critical (CVSS 10.0) unauthenticated remote code execution vulnerability affecting react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack across React 19.0 through 19.2.0, caused by a payload-deserialization flaw at React Server Function endpoints.

Developers were urged to upgrade immediately to patched versions, and downstream frameworks like Next.js and React Router shipped corresponding patches.

Full details: https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components