CVE detail
CVE-2025-55182
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 18.0
Why it matters now
Mention timeline
- Total mentions
- 2
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
49 source links · newest first
d SSH credentials and a range of known vulnerabilities in routers, cameras, and IoT devices, including recent ones like CVE-2025-55182 and older ones like CVE-2017-17215 in Huawei devices that remain unpatched across large device fleets. The FTP banner on the download servers reads: “220 cool ftp server hosted on brian krebs’ giant ass 4head.” Apparent
newssecurityaffairs.comJul 28, 2026, 7:07 PM- FBI: TeamPCP Compromised Dev Tools to Steal Cloud CredentialsSecurity Affairs
FBI says TeamPCP poisoned trusted developer tools to steal cloud credentials, spread malware through software updates, and extort victims. On July 2, 2026, the FBI published a FLASH alert identifying the criminal group called TeamPCP and detailing how it compromised widely used developer and security tools to steal credentials from victim environments at scale. The […]
newssecurityaffairs.comJul 4, 2026, 7:55 AM - AI Threat Landscape Digest March-April 2026Check Point Research
earchers identified an exposed operator server. Bissa is a modular mass-exploitation platform built around React2Shell (CVE-2025-55182), with 900+ confirmed compromises across millions of scanned Next.js endpoints and an archive of 30,000+ distinct .env filenames recovered from operator-controlled S3 storage. The operation has been running since Septem
vendorresearch.checkpoint.comMay 26, 2026, 10:09 AM - AI shrinks vulnerability exploitation window to hoursHelp Net Security
Time has become organizations’ biggest vulnerability because the gap between vulnerability discovery and exploitation has narrowed to hours, according to Synack’s 2026 State of Vulnerabilities Report. Total vulnerabilities by severity (2022-2025) (Source: Synack) AI expands the attack surface Agentic AI systems that act autonomously across systems introduce new risks that require human expertise to identify and understand. Automated scanning detects known signatures but can miss logic flaws, misconfigurations, and unexpected behavior. In 2025, mean time … More →
newswww.helpnetsecurity.comMay 18, 2026, 5:00 AM The malware framework targets web applications and cloud environments, including AWS, Docker, Kubernetes, and more.
newswww.securityweek.comMay 8, 2026, 8:32 AM- Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in AsiaTrend Micro Research
d them targeting server-based N-day vulnerabilities, such as the ProxyLogon chain targeting Microsoft Exchange Server ( CVE-2021-26855 , CVE-2021-26857 , CVE-2021-26858 , and CVE-2021-27065 ). Despite their age, these vulnerabilities remain effective exploits in unpatched environments. After compromising the server, the group used their access to insta
vendorwww.trendmicro.comApr 30, 2026, 12:00 AM - 27th April – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 27th April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Vercel, a frontend cloud platform, has disclosed a security incident linked to a compromise at Context.ai, where stolen OAuth tokens enabled unauthorized access through a connected app. The company reported access to employee […]
vendorresearch.checkpoint.comApr 27, 2026, 12:07 PM Security vendor Pluto Security has published details of a critical vulnerability in the open-source nginx UI web server configuration tool that has been under active exploitation by cybercriminals since March. News of the flaw, identified as CVE-2026-33032, first appeared on the National Vulnerability Database (NVD) on March 30, the same day that threat intelligence companies […]
newswww.csoonline.comApr 15, 2026, 8:52 PMUnit 42 uncovers escalating Kubernetes attacks, detailing how threat actors exploit identities and critical vulnerabilities to compromise cloud environments.
vendorunit42.paloaltonetworks.comApr 6, 2026, 10:00 PMAn apparent security lapse has allowed researchers to peer into the work of a threat group currently exploiting unpatched servers open to the four-month-old React2Shell vulnerability to steal login credentials, keys, and tokens at scale. Researchers from Cisco Systems’ Talos threat intelligence team who made the discovery said Thursday that the data harvested by an […]
newswww.csoonline.comApr 3, 2026, 7:10 PMUsing automated scanning and the Nexus Listener collection framework, the hackers compromised over 750 systems.
newswww.securityweek.comApr 3, 2026, 10:55 AM- Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security InfrastructureUnit42
TeamPCP continues its string of supply chain attacks, and announces a partnership with Vect ransomware group.
vendorunit42.paloaltonetworks.comMar 31, 2026, 9:00 PM - RondoDox botnet expands arsenal targeting 174 flaws, and hits 15,000 daily exploit attemptsSecurity Affairs
RondoDox botnet targets 174 flaws, reaching 15,000 daily exploit attempts in a more focused and strategic campaign. RondoDox botnet is ramping up attacks, targeting 174 vulnerabilities with up to 15,000 daily exploitation attempts in a more focused and strategic campaign, Bitsight reported. “We gathered all these exploit attempts (identifiable by indicators like the User-Agent and […]
newssecurityaffairs.comMar 17, 2026, 3:01 PM ENISA’s first Technical Advisory on Secure Package Managers helps developers safely use third-party packages. ENISA has released its first Technical Advisory on Package Managers, focusing on how developers can safely consume third-party packages. The document (March 2026, v1.1) follows public feedback incorporating 15 contributions from stakeholders, experts, and the open-source community. “This document focuses on […]
newssecurityaffairs.comMar 12, 2026, 8:49 AM- Edge systems take the brunt of internet-wide exploitation attemptsHelp Net Security
Internet-facing VPNs, routers, and remote access services absorbed sustained exploitation attempts throughout the second half of 2025, with nearly 3 billion malicious sessions recorded over 162 days. The concentration on edge infrastructure aligns with how attackers pursue initial access across the public internet. GreyNoise’s State of the Edge data set covers 2.97 billion sessions observed between July 23 and December 31, 2025, across sensors in more than 80 countries. Activity averaged roughly 212 malicious sessions … More →
newswww.helpnetsecurity.comFeb 25, 2026, 5:00 AM Threat actors exploiting the React2Shell vulnerability in components of React servers are using their access to compromise web domains and divert web traffic for malicious purposes. That’s the conclusion of researchers at Datadog Security Labs, who said in a blog Wednesday that the primary targets are sites running the NGINX open-source web server managed with […]
newswww.csoonline.comFeb 4, 2026, 10:00 PMTwo IP addresses accounted for the majority of the 1.4 million exploitation attempts observed over the past week.
newswww.securityweek.comFeb 4, 2026, 10:00 AMResponsible disclosure is built on an assumption that “doing the right thing” will be met with timely action, fair treatment, and professional respect, if not a bounty award. Increasingly, that assumption is failing. And when it does, organizations alienate researchers and create regulatory, legal, and reputational risk. Over the past few years, security researchers have […]
newswww.csoonline.comFeb 2, 2026, 7:00 AM- React Server Components Exploitation Consolidates as Two IPs Generate Majority of Attack TrafficGreyNoise
Two months after CVE-2025-55182 was disclosed on December 3, 2025, exploitation activity targeting React Server Components has consolidated significantly.
vendorwww.greynoise.ioFeb 2, 2026, 12:00 AM Threat actors are hunting for misconfigured proxy servers to gain access to APIs for various LLMs.
newswww.securityweek.comJan 12, 2026, 11:53 AMIn December, the botnet’s operators focused on weaponizing the flaw to compromise vulnerable Next.js servers.
newswww.securityweek.comJan 2, 2026, 11:12 AMRondoDox botnet exploits the critical React2Shell flaw (CVE-2025-55182) to infect vulnerable Next.js servers with malware and cryptominers. CloudSEK researchers warn that the RondoDox botnet is exploiting the critical React2Shell flaw (CVE-2025-55182) to drop malware and cryptominers on vulnerable Next.js servers. “CloudSEK’s report details a persistent nine-month RondoDoX botnet campaign targeting IoT devices and web applications. Recently, the […]
newssecurityaffairs.comJan 1, 2026, 2:31 PMAttackers have upped the ante in their exploits of a recently-disclosed maximum severity vulnerability in React Server Components (RSC), Next.js, and related frameworks. Financially-motivated attackers have found a way to use the flaw, dubbed React2Shell (CVE-2025-55182), to execute arbitrary code on vulnerable servers through a single malicious HTTP request. This allows them to quickly and […]
newswww.csoonline.comDec 19, 2025, 2:43 AM- More than half of public vulnerabilities bypass leading WAFsHelp Net Security
Miggo Security has released a new report that examines how web application firewalls are used across real-world security programs. The research outlines the role WAFs play as foundational infrastructure and evaluates their effectiveness against critical vulnerabilities, CVEs, and AI-driven threats. The report also explores how the WAF’s edge placement, combined with runtime intelligence, can support a more reliable and AI-ready mitigation layer for modern defense strategies. “This study clarifies that WAFs are currently an underutilized … More →
newswww.helpnetsecurity.comDec 18, 2025, 11:00 AM Google has also mentioned seeing React2Shell attacks conducted by Iranian threat actors.
newswww.securityweek.comDec 15, 2025, 1:48 PM- SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 75Security Affairs
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter UDPGangster Campaigns Target Multiple Countries Ransomware Trends in Bank Secrecy Act Data Between 2022 and 2024 Return of ClayRat: Expanded Features and Techniques SEEDSNATCHER : Dissecting an Android Malware Targeting Multiple Crypto Wallet Mnemonic […]
newssecurityaffairs.comDec 14, 2025, 2:22 PM A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Experts found an unsecured 16TB database containing 4.3B professional records Germany calls in Russian Ambassador over […]
newssecurityaffairs.comDec 14, 2025, 2:03 PMWe discuss the CVSS 10.0-rated RCE vulnerability in the Flight protocol used by React Server Components. This is tracked as CVE-2025-55182.
vendorunit42.paloaltonetworks.comDec 12, 2025, 9:40 PMSecurity firms have seen cryptocurrency miners, Linux backdoors, botnet malware, and various post-exploitation implants in React2Shell attacks.
newswww.securityweek.comDec 11, 2025, 12:12 PMNK-linked hackers are likely exploiting the React2Shell flaw to deploy a newly discovered remote access trojan, dubbed EtherRAT. North Korea–linked threat actors are likely exploiting the new critical React2Shell flaw (CVE-2025-55182) to deploy a previously unknown remote access trojan called EtherRAT, Sysdig researchers warn. The vulnerability CVE-2025-55182, is a pre-authentication remote code execution issue in React […]
newssecurityaffairs.comDec 10, 2025, 2:45 PM- CVE-2025-55182: React2Shell Analysis, Proof-of-Concept Chaos, and In-the-Wild ExploitationTrend Micro Research
CVE-2025-55182 is a CVSS 10.0 pre-authentication RCE affecting React Server Components. Amid the flood of fake proof-of-concept exploits, scanners, exploits, and widespread misconceptions, this technical analysis intends to cut throug
vendorwww.trendmicro.comDec 10, 2025, 12:00 AM North Korean threat actors are believed to be behind CVE-2025-55182 exploitation delivering EtherRAT.
newswww.securityweek.comDec 9, 2025, 3:18 PMMultiple China-linked threat actors began exploiting the CVE-2025-55182, aka React2Shell flaw, within hours, AWS Security warns. Multiple China-linked threat actors began exploiting the CVE-2025-55182, also known as the React2Shell flaw, within hours, according to AWS Security. The researchers confirmed that this vulnerability doesn’t affect AWS services, however they opted to share threat intelligence data to […]
newssecurityaffairs.comDec 8, 2025, 1:37 PM- 8th December – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 8th December, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The University of Pennsylvania and the University of Phoenix were hit by data breaches after attackers exploited zero-day vulnerabilities in Oracle E-Business Suite servers. At least 1,488 people at UPenn and numerous […]
vendorresearch.checkpoint.comDec 8, 2025, 1:07 PM - Exploitation of React2Shell SurgesSecurityWeek
An increasing number of threat actors have been attempting to exploit the React vulnerability CVE-2025-55182 in their attacks.
newswww.securityweek.comDec 8, 2025, 9:43 AM - U.S. CISA adds a Meta React Server Components flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Meta React Server Components flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Meta React Server Components flaw, tracked as CVE-2025-55182 (CVSS Score of 10.0), to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is a pre-authentication remote code execution vulnerability […]
newssecurityaffairs.comDec 8, 2025, 9:01 AM A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Attackers launch dual campaign on GlobalProtect portals and SonicWall APIs Maximum-severity XXE vulnerability discovered in Apache […]
newssecurityaffairs.comDec 7, 2025, 6:12 PM- Week in review: React, Node.js flaw patched, ransomware intrusion exposes espionage footholdHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Creative cybersecurity strategies for resource-constrained institutions In this Help Net Security interview, Dennis Pickett, CISO at RTI International, talks about how research institutions can approach cybersecurity with limited resources and still build resilience. He discusses the tension between open research and the need to protect sensitive information, noting that workable solutions come from understanding how people get their jobs done. … More →
newswww.helpnetsecurity.comDec 7, 2025, 9:00 AM - CVE-2025-55182Horizon3.ai
React Server Components RCE | Rapid Response
exploithorizon3.aiDec 5, 2025, 11:40 PM Plugging the React2Shell vulnerability in the open source React server and Next.js in IT environments has just become even more urgent with reports that exploits are already in the wild. Researchers at Greynoise said today they are seeing “opportunistic, largely automated exploitation attempts” trying to take advantage of the unsafe deserialization vulnerability in React Server […]
newswww.csoonline.comDec 5, 2025, 11:10 PMThe critical React vulnerability has been exploited in the wild by Chinese and other threat actors.
newswww.securityweek.comDec 5, 2025, 3:12 PM- How to detect React2Shell with Burp SuitePortSwigger Blog
Detecting React2Shell with Burp Suite Two new critical vulnerabilities, collectively known as React2Shell (CVE-2025-55182 and CVE-2025-66478), are rapidly gaining traction in the security community. D
newsportswigger.netDec 5, 2025, 1:53 PM Cloudflare’s network suffered a brief but widespread outage Friday, after an update to its Web Application Firewall to mitigate a vulnerability in React Server Components went wrong. At 9:09 a.m. UTC, the company reported that it was investigating issues with the Cloudflare Dashboard and related APIs, warning that customers might see requests fail or errors […]
newswww.csoonline.comDec 5, 2025, 11:21 AMAWS has seen multiple China-linked threat groups attempting to exploit the React vulnerability CVE-2025-55182.
newswww.securityweek.comDec 5, 2025, 7:33 AMisclosed React Server Components (RSC) “Flight” protocol RCE—often referred to publicly as “React2Shell” and tracked as CVE-2025-55182.
vendorwww.greynoise.ioDec 5, 2025, 12:00 AM- Critical React Server Components Vulnerability CVE-2025-55182: What Security Teams Need to KnowTrend Micro Research
CVE-2025-55182 is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability affecting React Server Components used in React.js, Next.js, and related frameworks (see the context section for a more exhaustive list of
vendorwww.trendmicro.comDec 5, 2025, 12:00 AM A critical vulnerability (CVE-2025-55182) in React Server Components (RSC) may allow unauthenticated attackers to achieve remote code exection on the application server, the React development team warned on Wednesday. The maximum-severity vulnerability was privately reported by Lachlan Davidson and has been fixed. At this moment, there are no public reports of it being exploited by attackers and no confirmed public PoC exploits (for now). Nevertheless, affected users have been advised to upgrade to a non-vulnerable … More →
newswww.helpnetsecurity.comDec 4, 2025, 12:23 PMA researcher has pointed out that only instances using a newer feature are impacted by CVE-2025-55182.
newswww.securityweek.comDec 4, 2025, 10:06 AMDevelopers using the React 19 library for building application interfaces are urged to immediately upgrade to the latest version because of a critical vulnerability that can be easily exploited by an attacker to remotely run their own code. Researchers at Wiz said Wednesday that a vulnerability in the React Server Components (RSC) Flight protocol affects […]
newswww.csoonline.comDec 4, 2025, 12:28 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
7 repository references · best confidence 0.99 · max 3 stars
- olezhaku/react2shell-toolkitHigh confidencegithubDiscovery source unavailable3 starsDiscovered Jul 9, 2026, 1:19 AM
- captain4554/CVE-2025-55182-ScannerHigh confidencegithubDiscovery source unavailable1 starsDiscovered Jul 9, 2026, 1:19 AM
- amnsecurity/reactorwatch-pentestHigh confidencegithubDiscovery source unavailable1 starsDiscovered Jul 10, 2026, 6:51 AM
- Mayca369/CVE-2025-55182High confidencegithubDiscovery source unavailable1 starsDiscovered Jul 9, 2026, 1:19 AM
- mayank729/CVE-2025-55182-scannerHigh confidencegithubDiscovery source unavailable0 starsDiscovered Jul 9, 2026, 1:19 AM
- alyaapm/CVE-2025-55182-shellinteractiveHigh confidencegithubDiscovery source unavailable0 starsDiscovered Jul 9, 2026, 1:19 AM
- Farhan9488/CVE-2025-55182-researchHigh confidencegithubDiscovery source unavailable0 starsDiscovered Jul 9, 2026, 1:19 AM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-67779CVSS 7.5 · High
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Comp…
- CVE-2025-55184CVSS 7.5 · High
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following p…
- CVE-2026-23864CVSS 7.5 · High
Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-do…
- CVE-2025-55183CVSS 5.3 · Medium
An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the fol…
1 mention - CVE-2026-57859CVSS 7.7 · High
e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band database write access to execut…
- CVE-2026-1360CVSS 7.5 · High
The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_fiel…