CVE-2025-55182

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-55182
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55182.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-55182
Aliases
Published
2025-12-03T16:15:56.463Z
Modified
2025-12-12T02:55:43.588444Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

References

Affected packages

Git / github.com/vercel/next.js

Affected ranges

Type
GIT
Repo
https://github.com/vercel/next.js
Events

Affected versions

v15.*

v15.0.0
v15.0.1
v15.0.1-canary.0
v15.0.1-canary.1
v15.0.1-canary.2
v15.0.1-canary.3
v15.0.2
v15.0.2-canary.0
v15.0.2-canary.1
v15.0.2-canary.10
v15.0.2-canary.11
v15.0.2-canary.2
v15.0.2-canary.3
v15.0.2-canary.4
v15.0.2-canary.5
v15.0.2-canary.6
v15.0.2-canary.7
v15.0.2-canary.8
v15.0.2-canary.9
v15.0.3
v15.0.3-canary.0
v15.0.3-canary.1
v15.0.3-canary.2
v15.0.3-canary.3
v15.0.3-canary.4
v15.0.3-canary.5
v15.0.3-canary.6
v15.0.3-canary.7
v15.0.3-canary.8
v15.0.3-canary.9
v15.0.4

Database specific

source

"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55182.json"