

UpGuard now detects a critical remote code execution vulnerability (CVSS 10.0) disclosed on December 3rd, 2025 affecting React Server Components and Next.js applications. This vulnerability allows unauthenticated attackers to execute arbitrary code on vulnerable servers through specially crafted HTTP requests, impacting millions of web applications globally.
CVE-2025-55182 affects React Server Components packages (react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack) in versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0.
Vendor Risk customers can now see if their vendors are impacted by these vulnerabilities, enabling proactive engagement before a breach impacts your supply chain. Breach Risk customers can see if their own infrastructure is impacted, allowing immediate remediation of exposed assets.
.png)





