Skip to main content

CVE detail

CVE-2025-55182

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

CVSS 10.0 · CriticalBuzz score 93.0KEV listed7 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 93.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 18.0
Mention score
30.0
49 evidence mentions in the snapshot
Diversity score
20.0
10 sources across 3 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
18.0
7 repos · best confidence 0.99
Best PoC traction
3
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
2
within the 30d window
Peak daily
1
highest bucket

Evidence

Source links by recency

Newest mentions first
49 source links · newest first
  • d SSH credentials and a range of known vulnerabilities in routers, cameras, and IoT devices, including recent ones like CVE-2025-55182 and older ones like CVE-2017-17215 in Huawei devices that remain unpatched across large device fleets. The FTP banner on the download servers reads: “220 cool ftp server hosted on brian krebs’ giant ass 4head.” Apparent

    newssecurityaffairs.comJul 28, 2026, 7:07 PM
  • FBI says TeamPCP poisoned trusted developer tools to steal cloud credentials, spread malware through software updates, and extort victims. On July 2, 2026, the FBI published a FLASH alert identifying the criminal group called TeamPCP and detailing how it compromised widely used developer and security tools to steal credentials from victim environments at scale. The […]

    newssecurityaffairs.comJul 4, 2026, 7:55 AM
  • AI Threat Landscape Digest March-April 2026Check Point Research

    earchers identified an exposed operator server. Bissa is a modular mass-exploitation platform built around React2Shell (CVE-2025-55182), with 900+ confirmed compromises across millions of scanned Next.js endpoints and an archive of 30,000+ distinct .env filenames recovered from operator-controlled S3 storage. The operation has been running since Septem

    vendorresearch.checkpoint.comMay 26, 2026, 10:09 AM
  • Time has become organizations’ biggest vulnerability because the gap between vulnerability discovery and exploitation has narrowed to hours, according to Synack’s 2026 State of Vulnerabilities Report. Total vulnerabilities by severity (2022-2025) (Source: Synack) AI expands the attack surface Agentic AI systems that act autonomously across systems introduce new risks that require human expertise to identify and understand. Automated scanning detects known signatures but can miss logic flaws, misconfigurations, and unexpected behavior. In 2025, mean time … More →

    newswww.helpnetsecurity.comMay 18, 2026, 5:00 AM
  • The malware framework targets web applications and cloud environments, including AWS, Docker, Kubernetes, and more.

    newswww.securityweek.comMay 8, 2026, 8:32 AM
  • d them targeting server-based N-day vulnerabilities, such as the ProxyLogon chain targeting Microsoft Exchange Server ( CVE-2021-26855 , CVE-2021-26857 , CVE-2021-26858 , and CVE-2021-27065 ). Despite their age, these vulnerabilities remain effective exploits in unpatched environments. After compromising the server, the group used their access to insta

    vendorwww.trendmicro.comApr 30, 2026, 12:00 AM
  • 27th April – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 27th April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Vercel, a frontend cloud platform, has disclosed a security incident linked to a compromise at Context.ai, where stolen OAuth tokens enabled unauthorized access through a connected app. The company reported access to employee […]

    vendorresearch.checkpoint.comApr 27, 2026, 12:07 PM
  • Security vendor Pluto Security has published details of a critical vulnerability in the open-source nginx UI web server configuration tool that has been under active exploitation by cybercriminals since March. News of the flaw, identified as CVE-2026-33032, first appeared on the National Vulnerability Database (NVD) on March 30, the same day that threat intelligence companies […]

    newswww.csoonline.comApr 15, 2026, 8:52 PM
  • Unit 42 uncovers escalating Kubernetes attacks, detailing how threat actors exploit identities and critical vulnerabilities to compromise cloud environments.

    vendorunit42.paloaltonetworks.comApr 6, 2026, 10:00 PM
  • An apparent security lapse has allowed researchers to peer into the work of a threat group currently exploiting unpatched servers open to the four-month-old React2Shell vulnerability to steal login credentials, keys, and tokens at scale. Researchers from Cisco Systems’ Talos threat intelligence team who made the discovery said Thursday that the data harvested by an […]

    newswww.csoonline.comApr 3, 2026, 7:10 PM
  • Using automated scanning and the Nexus Listener collection framework, the hackers compromised over 750 systems.

    newswww.securityweek.comApr 3, 2026, 10:55 AM
  • TeamPCP continues its string of supply chain attacks, and announces a partnership with Vect ransomware group.

    vendorunit42.paloaltonetworks.comMar 31, 2026, 9:00 PM
  • RondoDox botnet targets 174 flaws, reaching 15,000 daily exploit attempts in a more focused and strategic campaign. RondoDox botnet is ramping up attacks, targeting 174 vulnerabilities with up to 15,000 daily exploitation attempts in a more focused and strategic campaign, Bitsight reported. “We gathered all these exploit attempts (identifiable by indicators like the User-Agent and […]

    newssecurityaffairs.comMar 17, 2026, 3:01 PM
  • ENISA’s first Technical Advisory on Secure Package Managers helps developers safely use third-party packages. ENISA has released its first Technical Advisory on Package Managers, focusing on how developers can safely consume third-party packages. The document (March 2026, v1.1) follows public feedback incorporating 15 contributions from stakeholders, experts, and the open-source community. “This document focuses on […]

    newssecurityaffairs.comMar 12, 2026, 8:49 AM
  • Internet-facing VPNs, routers, and remote access services absorbed sustained exploitation attempts throughout the second half of 2025, with nearly 3 billion malicious sessions recorded over 162 days. The concentration on edge infrastructure aligns with how attackers pursue initial access across the public internet. GreyNoise’s State of the Edge data set covers 2.97 billion sessions observed between July 23 and December 31, 2025, across sensors in more than 80 countries. Activity averaged roughly 212 malicious sessions … More →

    newswww.helpnetsecurity.comFeb 25, 2026, 5:00 AM
  • Threat actors exploiting the React2Shell vulnerability in components of React servers are using their access to compromise web domains and divert web traffic for malicious purposes. That’s the conclusion of researchers at Datadog Security Labs, who said in a blog Wednesday that the primary targets are sites running the NGINX open-source web server managed with […]

    newswww.csoonline.comFeb 4, 2026, 10:00 PM
  • Two IP addresses accounted for the majority of the 1.4 million exploitation attempts observed over the past week.

    newswww.securityweek.comFeb 4, 2026, 10:00 AM
  • Responsible disclosure is built on an assumption that “doing the right thing” will be met with timely action, fair treatment, and professional respect, if not a bounty award. Increasingly, that assumption is failing. And when it does, organizations alienate researchers and create regulatory, legal, and reputational risk. Over the past few years, security researchers have […]

    newswww.csoonline.comFeb 2, 2026, 7:00 AM
  • Two months after CVE-2025-55182 was disclosed on December 3, 2025, exploitation activity targeting React Server Components has consolidated significantly.

    vendorwww.greynoise.ioFeb 2, 2026, 12:00 AM
  • Threat actors are hunting for misconfigured proxy servers to gain access to APIs for various LLMs.

    newswww.securityweek.comJan 12, 2026, 11:53 AM
  • In December, the botnet’s operators focused on weaponizing the flaw to compromise vulnerable Next.js servers.

    newswww.securityweek.comJan 2, 2026, 11:12 AM
  • RondoDox botnet exploits the critical React2Shell flaw (CVE-2025-55182) to infect vulnerable Next.js servers with malware and cryptominers. CloudSEK researchers warn that the RondoDox botnet is exploiting the critical React2Shell flaw (CVE-2025-55182) to drop malware and cryptominers on vulnerable Next.js servers. “CloudSEK’s report details a persistent nine-month RondoDoX botnet campaign targeting IoT devices and web applications. Recently, the […]

    newssecurityaffairs.comJan 1, 2026, 2:31 PM
  • Attackers have upped the ante in their exploits of a recently-disclosed maximum severity vulnerability in React Server Components (RSC), Next.js, and related frameworks. Financially-motivated attackers have found a way to use the flaw, dubbed React2Shell (CVE-2025-55182), to execute arbitrary code on vulnerable servers through a single malicious HTTP request. This allows them to quickly and […]

    newswww.csoonline.comDec 19, 2025, 2:43 AM
  • Miggo Security has released a new report that examines how web application firewalls are used across real-world security programs. The research outlines the role WAFs play as foundational infrastructure and evaluates their effectiveness against critical vulnerabilities, CVEs, and AI-driven threats. The report also explores how the WAF’s edge placement, combined with runtime intelligence, can support a more reliable and AI-ready mitigation layer for modern defense strategies. “This study clarifies that WAFs are currently an underutilized … More →

    newswww.helpnetsecurity.comDec 18, 2025, 11:00 AM
  • Google has also mentioned seeing React2Shell attacks conducted by Iranian threat actors.

    newswww.securityweek.comDec 15, 2025, 1:48 PM
  • SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 75Security Affairs

    Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter UDPGangster Campaigns Target Multiple Countries Ransomware Trends in Bank Secrecy Act Data Between 2022 and 2024 Return of ClayRat: Expanded Features and Techniques SEEDSNATCHER : Dissecting an Android Malware Targeting Multiple Crypto Wallet Mnemonic […]

    newssecurityaffairs.comDec 14, 2025, 2:22 PM
  • A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Experts found an unsecured 16TB database containing 4.3B professional records Germany calls in Russian Ambassador over […]

    newssecurityaffairs.comDec 14, 2025, 2:03 PM
  • We discuss the CVSS 10.0-rated RCE vulnerability in the Flight protocol used by React Server Components. This is tracked as CVE-2025-55182.

    vendorunit42.paloaltonetworks.comDec 12, 2025, 9:40 PM
  • Security firms have seen cryptocurrency miners, Linux backdoors, botnet malware, and various post-exploitation implants in React2Shell attacks.

    newswww.securityweek.comDec 11, 2025, 12:12 PM
  • NK-linked hackers are likely exploiting the React2Shell flaw to deploy a newly discovered remote access trojan, dubbed EtherRAT. North Korea–linked threat actors are likely exploiting the new critical React2Shell flaw (CVE-2025-55182) to deploy a previously unknown remote access trojan called EtherRAT, Sysdig researchers warn. The vulnerability CVE-2025-55182, is a pre-authentication remote code execution issue in React […]

    newssecurityaffairs.comDec 10, 2025, 2:45 PM
  • CVE-2025-55182 is a CVSS 10.0 pre-authentication RCE affecting React Server Components. Amid the flood of fake proof-of-concept exploits, scanners, exploits, and widespread misconceptions, this technical analysis intends to cut throug

    vendorwww.trendmicro.comDec 10, 2025, 12:00 AM
  • North Korean threat actors are believed to be behind CVE-2025-55182 exploitation delivering EtherRAT.

    newswww.securityweek.comDec 9, 2025, 3:18 PM
  • Multiple China-linked threat actors began exploiting the CVE-2025-55182, aka React2Shell flaw, within hours, AWS Security warns. Multiple China-linked threat actors began exploiting the CVE-2025-55182, also known as the React2Shell flaw, within hours, according to AWS Security. The researchers confirmed that this vulnerability doesn’t affect AWS services, however they opted to share threat intelligence data to […]

    newssecurityaffairs.comDec 8, 2025, 1:37 PM
  • 8th December – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 8th December, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The University of Pennsylvania and the University of Phoenix were hit by data breaches after attackers exploited zero-day vulnerabilities in Oracle E-Business Suite servers. At least 1,488 people at UPenn and numerous […]

    vendorresearch.checkpoint.comDec 8, 2025, 1:07 PM
  • Exploitation of React2Shell SurgesSecurityWeek

    An increasing number of threat actors have been attempting to exploit the React vulnerability CVE-2025-55182 in their attacks.

    newswww.securityweek.comDec 8, 2025, 9:43 AM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Meta React Server Components flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Meta React Server Components flaw, tracked as CVE-2025-55182 (CVSS Score of 10.0), to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is a pre-authentication remote code execution vulnerability […]

    newssecurityaffairs.comDec 8, 2025, 9:01 AM
  • A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Attackers launch dual campaign on GlobalProtect portals and SonicWall APIs Maximum-severity XXE vulnerability discovered in Apache […]

    newssecurityaffairs.comDec 7, 2025, 6:12 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Creative cybersecurity strategies for resource-constrained institutions In this Help Net Security interview, Dennis Pickett, CISO at RTI International, talks about how research institutions can approach cybersecurity with limited resources and still build resilience. He discusses the tension between open research and the need to protect sensitive information, noting that workable solutions come from understanding how people get their jobs done. … More →

    newswww.helpnetsecurity.comDec 7, 2025, 9:00 AM
  • CVE-2025-55182Horizon3.ai

    React Server Components RCE | Rapid Response

    exploithorizon3.aiDec 5, 2025, 11:40 PM
  • Plugging the React2Shell vulnerability in the open source React server and Next.js in IT environments has just become even more urgent with reports that exploits are already in the wild. Researchers at Greynoise said today they are seeing “opportunistic, largely automated exploitation attempts” trying to take advantage of the unsafe deserialization vulnerability in React Server […]

    newswww.csoonline.comDec 5, 2025, 11:10 PM
  • The critical React vulnerability has been exploited in the wild by Chinese and other threat actors.

    newswww.securityweek.comDec 5, 2025, 3:12 PM
  • How to detect React2Shell with Burp SuitePortSwigger Blog

    Detecting React2Shell with Burp Suite Two new critical vulnerabilities, collectively known as React2Shell (CVE-2025-55182 and CVE-2025-66478), are rapidly gaining traction in the security community. D

    newsportswigger.netDec 5, 2025, 1:53 PM
  • Cloudflare’s network suffered a brief but widespread outage Friday, after an update to its Web Application Firewall to mitigate a vulnerability in React Server Components went wrong. At 9:09 a.m. UTC, the company reported that it was investigating issues with the Cloudflare Dashboard and related APIs, warning that customers might see requests fail or errors […]

    newswww.csoonline.comDec 5, 2025, 11:21 AM
  • AWS has seen multiple China-linked threat groups attempting to exploit the React vulnerability CVE-2025-55182.

    newswww.securityweek.comDec 5, 2025, 7:33 AM
  • isclosed React Server Components (RSC) “Flight” protocol RCE—often referred to publicly as “React2Shell” and tracked as CVE-2025-55182.

    vendorwww.greynoise.ioDec 5, 2025, 12:00 AM
  • CVE-2025-55182 is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability affecting React Server Components used in React.js, Next.js, and related frameworks (see the context section for a more exhaustive list of

    vendorwww.trendmicro.comDec 5, 2025, 12:00 AM
  • A critical vulnerability (CVE-2025-55182) in React Server Components (RSC) may allow unauthenticated attackers to achieve remote code exection on the application server, the React development team warned on Wednesday. The maximum-severity vulnerability was privately reported by Lachlan Davidson and has been fixed. At this moment, there are no public reports of it being exploited by attackers and no confirmed public PoC exploits (for now). Nevertheless, affected users have been advised to upgrade to a non-vulnerable … More →

    newswww.helpnetsecurity.comDec 4, 2025, 12:23 PM
  • A researcher has pointed out that only instances using a newer feature are impacted by CVE-2025-55182.

    newswww.securityweek.comDec 4, 2025, 10:06 AM
  • Developers using the React 19 library for building application interfaces are urged to immediately upgrade to the latest version because of a critical vulnerability that can be easily exploited by an attacker to remotely run their own code. Researchers at Wiz said Wednesday that a vulnerability in the React Server Components (RSC) Flight protocol affects […]

    newswww.csoonline.comDec 4, 2025, 12:28 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

7 repository references · best confidence 0.99 · max 3 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2025-67779

    It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Comp…

    CVSS 7.5 · High
  • CVE-2025-55184

    A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following p…

    CVSS 7.5 · High
    1 mention
  • CVE-2026-23864

    Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-do…

    CVSS 7.5 · High
  • CVE-2025-55183

    An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the fol…

    CVSS 5.3 · Medium
    1 mention
  • CVE-2026-11536

    IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.

    CVSS 8.5 · High
    1 mention
  • CVE-2026-12118

    IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted da…

    CVSS 9.8 · Critical
    1 mention