CVE-2025-55182: Critical Unauthenticated RCE in React Server Components via Insecure Deserialization

ISGroup Cybersecurity

React Server Components are a modern web development architecture that allows developers to create applications that combine server-side rendering with an interactive client-side experience. This technology is the foundation of frameworks like Next.js and is increasingly adopted for building high-performance, scalable web applications. Because it handles client requests on the server side, its security is critical to the integrity of the web application.

This vulnerability represents a critical risk, allowing for unauthenticated Remote Code Execution (RCE). The impact is a complete system compromise, with a CVSS score of 10.0. The difficulty for an attacker is low, as the vulnerability can be triggered with a single, specially crafted HTTP request to an exposed server endpoint.

Given that the vulnerability has been made public and proof-of-concept exploits are available, active use in real-world environments must be assumed. Any Internet-accessible application using vulnerable versions of React Server Components is at immediate risk of compromise. A successful attack can lead to severe data breaches, service disruptions, and chain attacks against the compromised infrastructure.

ProductReact Server Components
Date2025-12-03 16:50:52

Technical Summary

The root cause of this vulnerability is an insecure deserialization flaw within the data processing logic of Server Functions in React Server Components. The server does not properly sanitize or validate data received from the client before deserializing it.

The attack chain unfolds as follows:

  1. An unauthenticated attacker creates a malicious payload containing serialized data. This payload is designed to execute arbitrary code when processed by the server’s deserialization mechanism.
  2. The attacker sends this payload within an HTTP request to a publicly exposed Server Function endpoint.
  3. The server-side component receives the request and attempts to deserialize the untrusted payload.
  4. Due to the lack of validation, the deserialization process triggers the embedded malicious code, leading to arbitrary code execution with the permissions of the web server process.

An attacker can exploit this vulnerability to gain full control of the affected server, allowing them to steal sensitive data, install malware, or move laterally to other systems on the network.

Affected versions:

  • react-server-dom-parcel: versions 19.0.0 through 19.2.0
  • react-server-dom-turbopack: versions 19.0.0 through 19.2.0
  • react-server-dom-webpack: versions 19.0.0 through 19.2.0

A patch has been released, and you are urgently advised to update to the latest versions of these packages immediately.

Recommendations

  • Immediate Patching: Update all affected React Server Components packages (react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack) to the latest available versions. Do not delay patching, as active exploitation is highly likely.

  • Mitigations:

    • Implement a Web Application Firewall (WAF) with rules designed to inspect and block anomalous or malicious payloads related to deserialization in HTTP traffic. Several providers, such as Cloudflare, have already implemented virtual patching rules.
    • If patching cannot be performed immediately, temporarily restrict access to vulnerable web applications to trusted IP ranges, although this measure does not replace the patch.

  • Hunting & Monitoring:

    • Analyze HTTP server logs for unusual or malformed requests to Server Function endpoints. Pay attention to suspicious data patterns that do not match legitimate application traffic.
    • Monitor server processes to detect unexpected child processes, outbound network connections to unknown destinations, or unusual file modifications, all of which are potential indicators of compromise.

  • Incident Response:

    • In case of suspected compromise, immediately isolate the affected server from the network to prevent lateral movement.
    • Preserve server logs, memory dumps, and disk images for forensic analysis.
    • Assume that all credentials or secrets present on the compromised server have been exfiltrated and initiate rotation procedures.

  • Defense in Depth:

    • Run web application processes with the lowest possible privileges to limit the impact of a potential RCE.
    • Implement network segmentation to prevent a compromised web server from accessing critical internal systems.
    • Ensure that regular backups of critical data are maintained and stored in a secure, isolated location.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert