CVE-2025-55183 — Facebook React
As of 2025-12-12, CVE-2025-55183 is a MEDIUM-severity vulnerability in Facebook React, CVSS v3.1 5.3, EPSS 20.9% (95.6th percentile). Threadlinqs Intelligence links 1 tracked threat campaign to CVE-2025-55183, most recently “React2Shell CVE-2025-55182 — Multiple Threat Actors Actively Exploiting React Server Components RCE (CVSS 10.0)”.
Last updated: 2025-12-12
What is CVE-2025-55183?
An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically crafted HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Server Function. Exploitation requires the existence of a Server Function which explicitly or implicitly exposes a stringified argument.
The record classifies CVE-2025-55183 under weakness class NVD-CWE-noinfo. Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs no prior authentication, needs no user interaction. 83 affected-product entries are recorded, across 2 vendors, listed below. The identifier was first published 276 days ago.
Severity and exploitation probability
- CVSS v3.1 base score
- 5.3 — MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - EPSS (FIRST)
- 20.9% probability of exploitation in the next 30 days, higher than 95.6% of all scored CVEs
- CISA KEV
- Not listed in the CISA Known Exploited Vulnerabilities catalog
- Threadlinqs priority
- 6.5/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
- Published
- 2025-12-11, last modified 2025-12-12
Is CVE-2025-55183 being exploited?
It currently carries a trending score of 29 in the Threadlinqs vulnerability feed.
Affected products and versions
- Facebook: React
- Vercel: Next.js, Next.js 15.6.0, Next.js 16.1.0
Showing 4 of 83 recorded product entries.
How to fix CVE-2025-55183
Vendor advisory: https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components. Apply the vendor fix referenced above to every affected product listed in this record, then confirm the running version against the vendor advisory.
Threat activity tracking CVE-2025-55183
1 tracked threat in the Threadlinqs corpus references CVE-2025-55183, either in the campaign’s CVE list or as an indicator on the campaign record.
- React2Shell CVE-2025-55182 — Multiple Threat Actors Actively Exploiting React Server Components RCE (CVSS 10.0) — CRITICAL · 2026-02-13
Sources
Seeded from nvd and not yet processed by the Threadlinqs enrichment pipeline, so blank CVSS, EPSS or KEV fields above mean NOT MEASURED rather than measured-absent.
← all vulnerabilities · Markdown version · Threadlinqs Intelligence