Critical React2Shell Vulnerability (CVE-2025-55182) Analysis: Surge in Attacks Targeting RSC-Enabled Services Worldwide
Torrance, United States / California, December 12, 2025
Torrance, United States / California, December 12, 2025
In December 2025, a critical vulnerability designated as CVE-2025-55182, known as React2Shell, was disclosed. This vulnerability affects React Server Components (RSC) and permits remote code execution (RCE) without authentication. Following its disclosure, multiple security vendors reported increased scanning activity and potential exploitation attempts. The Cybersecurity and Infrastructure Security Agency (CISA) has included this flaw in its Known Exploited Vulnerabilities (KEV) catalog.
The vulnerability arises from a validation flaw in the deserialization process of the Flight protocol used by React Server Components. This flaw allows attackers to execute remote code by sending a crafted payload to the Server Functions endpoint. A proof-of-concept (PoC) is publicly available, increasing the risk of automated attacks. The impact extends to all services using RSC, including frameworks like Next.js, React Router RSC, Waku, Vite RSC Plugin, Parcel RSC Plugin, and RedwoodJS, all of which share a similar structure.
Updates to mitigate this vulnerability are available in the react-server-dom-* packages version 19.0.1, 19.1.2, 19.2.1, or later. The vulnerability is rated with a CVSS score of 10.0, indicating critical severity.
Detecting React2Shell using traditional methods is challenging because RSC components are not externally visible. Frameworks like Next.js, which internally vendor React modules, further complicate identification. Reliable detection involves analyzing HTTP response headers. Criminal IP has identified 109,487 RSC-enabled assets in the United States through header pattern analysis, highlighting a significant exposure risk.
This vulnerability affects React Server Components (RSC) and permits remote code execution (RCE) without authentication.
1. Immediate Update of React-Related Packages
Organizations should update all React-related packages to the latest patched versions. The react-server-dom-webpack package should be upgraded to versions 19.0.1, 19.1.2, or 19.2.1, while react-server-dom-parcel and react-server-dom-turbopack should be updated to version 19.0.1 or later.
2. Verify Patch Availability for Each Framework
React RSC is used across multiple frameworks. It is crucial to review each framework's security advisories and release notes to ensure that the vulnerability has been addressed in the upgraded versions.
3. Minimize External Exposure of RSC Endpoints
Access to RSC endpoints should be restricted using reverse proxies, web application firewalls (WAF), or authentication gateways where possible.
4. Leverage Criminal IP for Monitoring
Monitor exposure of RSC-related headers. Detect scanning attempts based on TLS fingerprints. Automatically block malicious scanning IPs. Check for vulnerability presence and associated Exploit DB entries.
React2Shell (CVE-2025-55182) is a significant vulnerability for React-based services, with a high risk of widespread exploitation due to its low complexity and available PoCs. Approximately 110,000 RSC-enabled services in the United States are exposed, necessitating immediate patch application and real-time monitoring as part of the response strategy. Criminal IP offers tools for effective monitoring and defense.
Criminal IP is a cyber threat intelligence platform by AI SPERA, used in over 150 countries. It provides comprehensive threat visibility and integrates with platforms like AWS, Microsoft Azure, and Snowflake for enhanced access to threat intelligence.
Based on reporting by Cyber Security News.
