React Server Components Pre-auth RCE Scanner
Scanning target for vulnerabilities...
CVE-2025-55182 and CVE-2025-66478 are pre-authentication remote code execution vulnerabilities in React Server Components (RSC).
| Product | Affected Versions | Fixed Versions |
|---|---|---|
| react-server-dom-webpack | 19.0 ~ 19.2.0 | 19.0.1, 19.1.2, 19.2.1 |
| react-server-dom-parcel | 19.0 ~ 19.2.0 | 19.0.1, 19.1.2, 19.2.1 |
| react-server-dom-turbopack | 19.0 ~ 19.2.0 | 19.0.1, 19.1.2, 19.2.1 |
| Next.js | 14.3.0-canary.77+, 15.x, 16.x | 15.0.5, 15.1.9, 15.2.6, etc. |