Skip to content

Vulnerabilities in React and Next.js

Critical
davydkov published GHSA-vr6p-vq2p-6j74 Dec 4, 2025

Package

npm react-server-dom-parcel (npm)

Affected versions

19.0.0, 19.1.0, 19.1.1, and 19.2.0

Patched versions

19.0.3, 19.1.4, and 19.2.3
npm react-server-dom-turbopack (npm)
19.0.0, 19.1.0, 19.1.1, and 19.2.0
19.0.3, 19.1.4, and 19.2.3
npm react-server-dom-webpack (npm)
19.0.0, 19.1.0, 19.1.1, and 19.2.0
19.0.3, 19.1.4, and 19.2.3

Description

The security team at my company just notified me about RCE vulnerabilities in React and Next.js: https://www.wiz.io/blog/critical-vulnerability-in-react-cve-2025-55182

I’m not sure if LikeC4 is currently impacted, but if so could you please release a version with patched dependencies? 🙏🏻

[2025-12-15] Edit: the last fixes published by React were not thorough, a new set of fix releases completes the mitigation; see https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components

Severity

Critical

CVE ID

CVE-2025-55182

Weaknesses

No CWEs

Credits