Over 644,000 Domains Exposed to Critical React Server Components Vulnerability
The Shadowserver Foundation has released new data regarding the exposure of web applications to CVE-2025-55182 , a critical vulnerability affecting React Server Components.
The Shadowserver Foundation has released new data regarding the exposure of web applications to CVE-2025-55182 , a critical vulnerability affecting React Server Components.
Recent improvements in scanning methodologies have identified an attack surface comprising over 165,000 unique IP addresses and more than 644,000 domains hosting vulnerable code as of December 8, 2025.
This increase in identified instances suggests that previous estimates of the vulnerability’s reach were significantly understated. The enhanced targeting capabilities deployed by Shadowserver have revealed that hundreds of thousands of websites are susceptible to exploitation.
CVE-2025-55182 targets the architecture of React Server Components, potentially allowing attackers to bypass security controls or execute unauthorized code on the server side if left unpatched.
The volume of affected domains highlights the pervasive nature of React in modern web development. Because React Server Components are integral to the rendering pipeline of high-performance web applications, a vulnerability at this layer poses significant risks to data integrity and server security.
The data indicates that the issue affects a broad spectrum of the internet, from small business sites to enterprise-grade platforms.
This increase in identified instances suggests that previous estimates of the vulnerability’s reach were significantly understated.
Security experts urge administrators to prioritize this patch. The exposure of over half a million domains creates a lucrative target environment for threat actors, who often automate attacks once a Proof of Concept (PoC) becomes available or scanning techniques are refined.
The updated statistics from Shadowserver indicate that the remediation window is closing rapidly.
Organizations utilizing React Server Components must verify their current versions against vendor advisories immediately.
The Shadowserver Foundation has provided a public dashboard to track the statistics of these vulnerable instances, encouraging transparency and rapid response within the cybersecurity community.
Administrators should check their logs for signs of compromise, as the vulnerability may have been present before enhanced scans detected the full scope of exposure.
CVE ID CVSS Score Affected Component Impact Vulnerable IPs
CVE-2025-55182 9.8 (Critical) React Server Components RCE / Security Bypass
165,000
Applying the official patches released by the React maintainers is the only definitive way to mitigate the risk. Until patches are applied, these 644,000 domains remain open to potential cyberattacks.
Based on reporting by Cyber Security News.
