A critical vulnerability in React Server Components (CVE 2025-55182) has been responsibly disclosed. It affects React 19 and frameworks that use it, including Next.js (CVE-2025-66478)
-
If you are using Next.js, every version between Next.js 15 and 16 is affected, and we recommend immediately updating to the latest Next.js version containing the appropriate fixes (15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7)
-
If you are using another framework using Server Components, we also recommend immediately updating to the latest React version containing the appropriate fixes (19.0.1, 19.1.2, and 19.2.1)
Vercel WAF rules provide an additional layer of defense by filtering known exploit patterns. However, WAF rules cannot guarantee protection against all possible variants of an attack. Please upgrade to patched versions immediately.
https://vercel.com/changelog/summary-of-CVE-2025-55182






