Disclosure summary
Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 has been rejected, but it is associated with CVE-2025- 55182.
CISA remediation guidance
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
The DFIR Report · RSS-daed0f70c06056a0c2699f126e62ffab1b3
Open original source · Updated May 11, 2026
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
CVE mention in publisher metadata; check the original affected versions.
JPCERT/CC English blog · RSS-f18db47ae1e96796cde9fae307faa737b0b
Open original source · Updated Feb 12, 2026
Multiple Threat Actors Rapidly Exploit React2Shell: A Case Study of Active Compromise
CVE mention in publisher metadata; check the original affected versions.
Original records & references
PUBLISHED 2025-12-05T00:00:00-05:00
MODIFIED 2025-12-05T00:00:00-05:00
INGESTED 2026-10-06T11:42:57-04:00