Critical 10/10 flaw in React and Next.js lets attackers take over web servers

Reading Time: 5 min
18
techkahwa.net | 4 December 2025

The React team has disclosed a critical vulnerability in React Server Components that carries the maximum severity score of 10.0, and Next.js has confirmed that its apps are affected too. The short version for anyone running a modern React or Next.js site: upgrade to the latest patched release now, because Next.js says there is no workaround.

What happened

On 3 December 2025, the React team published an advisory that opens with a sentence no developer wants to read: “A critical unauthenticated remote code execution vulnerability exists in React Server Components.” It is tracked as CVE-2025-55182 and rated CVSS 10.0, the highest score on the scale.

In plain terms, “unauthenticated remote code execution” means an attacker does not need an account or a password. They could make a vulnerable server run code of their choosing, which amounts to taking control of it. I will leave the technical detail there on purpose. What matters for site owners is the fix, not the mechanics.

Next.js, which builds on React Server Components, issued its own advisory under CVE-2025-66478. Its message is blunt: there is no workaround, and “upgrading to a patched version is required.”

According to the React team, the flaw was reported on 29 November 2025 by researcher Lachlan Davidson through the Meta Bug Bounty program. That means the patch arrived within a few days of the report, which I find reassuring.

Who is affected

React says the vulnerable versions are 19.0, 19.1.0, 19.1.1 and 19.2.0 of three packages:

  • react-server-dom-webpack
  • react-server-dom-parcel
  • react-server-dom-turbopack

These packages are what make React Server Components work, and a project can depend on them without ever listing them by name.

Next.js lists these patched releases: 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7 and 16.0.7. Next.js 13.x, Next.js 14.x stable and apps built on the Pages Router are not affected.

In practice, the affected Next.js apps are those on versions 15 and 16 that use the App Router. This is not only a problem for large companies. Many small business sites, startup landing pages and client projects built by freelancers run on Next.js. If you built a site for a client this year, it is worth checking which version it runs.

By the numbers

Item Detail Source
React CVE CVE-2025-55182 React
Next.js CVE CVE-2025-66478 Next.js
Severity CVSS 10.0 (critical) React
Vulnerable React versions 19.0, 19.1.0, 19.1.1, 19.2.0 React
First fixed React versions 19.0.1, 19.1.2, 19.2.1 React
Patched Next.js versions 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7 Next.js
Not affected Next.js 13.x, 14.x stable, Pages Router apps Next.js
Date reported 29 November 2025 React
Workaround None, upgrade required Next.js

What to do now

These steps are based on the React and Next.js advisories.

  1. Find out which versions you run. Check your package.json and lock file for next and for the react-server-dom packages listed above.
  2. Upgrade to the latest patched release in your version line. For React Server Components that means at least 19.0.1, 19.1.2 or 19.2.1; for Next.js at least the patched release listed above for your minor version. If the React or Next.js teams publish a newer release in your line, install that one instead of stopping at the first fix.
  3. Rebuild and redeploy. Updating the dependency on your laptop does nothing until the new build is live on the server.
  4. Do not treat hosting or firewall protections as a substitute for patching. Next.js says plainly that upgrading is required.
  5. After patching and redeploying, rotate the application’s secrets and environment variables, such as API keys and database passwords. This is my own recommendation as a precaution for any site that was online and unpatched.

If you manage sites for clients, send them a short note today even if you plan to handle the update yourself. It builds trust, and it makes sure nobody assumes someone else took care of it.

Why it matters

React and Next.js power a huge share of the modern web. A flaw that scores 10.0 and needs no login sits at the worst end of the scale, so the gap between disclosure and patching is where the risk lives.

The good news is that the fix is a normal version upgrade. For most projects that means updating one or two dependencies, rebuilding and redeploying. My advice is simple: do it today, not at the next sprint planning, and keep an eye on the official advisories in case they are updated.

Sources

  • React, critical security vulnerability in React Server Components advisory, 3 December 2025, https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components
  • Next.js, security advisory for CVE-2025-66478, December 2025, https://nextjs.org/blog/CVE-2025-66478
  • NIST National Vulnerability Database, entry for CVE-2025-55182, December 2025, https://nvd.nist.gov/vuln/detail/CVE-2025-55182