Out-of-Band / Urgent Remediation
Listed in the CISA KEV catalog, and an EPSS probability of 0.998.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
Vulnerability type: CWE-502 — Deserialization of untrusted data
Impacted software or hardware
- react Software 19.0.0, 19.1.0, 19.1.1, 19.2.0
- next.js Software >= 15.0.0 < 15.0.5, >= 15.1.0 < 15.1.9, >= 15.2.0 < 15.2.6, >= 15.3.0 < 15.3.6, >= 15.4.0 < 15.4.8, >= 15.5.0 < 15.5.7, >= 16.0.0 < 16.0.7, 14.3.0, 15.6.0, 16.0.0
Patch status: Patch or fixed version identified
Fixed versions: next.js: update to 15.0.5 or later | next.js: update to 15.1.9 or later | next.js: update to 15.2.6 or later | next.js: update to 15.3.6 or later | next.js: update to 15.4.8 or later | next.js: update to 15.5.7 or later
Remediation: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Remediation basis: CISA KEV required action
CISA KEV: known exploited. Remediation due 2025-12-12. Known ransomware campaign use: Known.
Research this vulnerability
- NIST NVD — Scores, weaknesses, products, and references
- CVE.org — Authoritative CVE Program record
- CISA KEV — Known exploitation and federal remediation action
- Tenable — Detection plugins and Tenable analysis
- Rapid7 — Threat, exploit, and remediation research
- GitHub Advisory — Open-source package advisories
- Snyk — Package versions and available fixes