Skip to main content

React Server Components vulnerabilities

1 published alerts for Meta React Server Components.

Actively exploited (KEV)Ransomware

CVE-2025-55182

Meta React Server Components Remote Code Execution Vulnerability

Meta React Server Components is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-55182). Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182. CISA remediation due date: 2025-12-12. If you need help checking exposure, call (864) 335-9223.