
Additional React and Next.js RSC Vulnerabilities Lead to Denial-of-Service and Source Code Disclosure
Following the previously disclosed React2Shell remote code execution vulnerabilities (React: CVE-2025-55182, Next.js: CVE-2025-66478, CVSS 10.0), additional security issues were identified in React Server Components (RSC) during post-patch analysis. Three new vulnerabilities were disclosed: These issues do not introduce a new RCE vector, but they do require an additional upgrade, even in environments that already patched …










