Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
CISA KEV·Added 2025-12-05 — agencies required to remediate by 2025-12-12 · Ransomware
📦 npm

CVE-2025-55182

CRITICAL

React Server Components are Vulnerable to RCE

Also known asGHSA-fv66-9v8q-g76r
Published
Dec 3, 2025
Updated
Apr 10, 2026
Affected
9 pkgs
Patched
9 / 9
Exploits
111 known

EPSS Exploitation Probability

via FIRST.org ↗
83.2%probability of exploitation in next 30 days
Very High Risk99th percentile+1.19%
36.5%55.9%75.2%94.6%47.4%83.2%Jan 26Apr 26Jun 26

EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.

Blast Radius

9 pkgs affected
📦react-server-dom-webpack📦react-server-dom-webpack📦react-server-dom-webpack📦react-server-dom-turbopack📦react-server-dom-turbopack📦react-server-dom-turbopack📦react-server-dom-parcel📦react-server-dom-parcel+1 more

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects npm packages — download data is not available via public APIs for these ecosystems.

Description

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

Affected Packages

9 total 9 fixed
EcosystemPackageVulnerable rangeFix
📦npmreact-server-dom-webpack19.0.0&&< 19.0.119.0.1
📦npmreact-server-dom-webpack19.1.0&&< 19.1.219.1.2
📦npmreact-server-dom-webpack19.2.0&&< 19.2.119.2.1
📦npmreact-server-dom-turbopack19.0.0&&< 19.0.119.0.1
📦npmreact-server-dom-turbopack19.1.0&&< 19.1.219.1.2
📦npmreact-server-dom-turbopack19.2.0&&< 19.2.119.2.1
Exploits & PoCs
111

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

EDB-52506webappsmultiple

React Server 19.2.0 - Remote Code Execution

by danieljavanrad · Apr 9, 2026

Frequently Asked Questions

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
O3 Security · Impact-Aware SCA

Is CVE-2025-55182 in your stack?

O3 detects CVE-2025-55182 across npm dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.