patch&proof.
← The dispatch

open-source / Source brief

React Server Components received a critical unauthenticated RCE fix

The React team disclosed CVE-2025-55182, affecting several React Server DOM packages in versions 19.0, 19.1.0, 19.1.1 and 19.2.0. Patched versions were pu…

Historical backfill · prepared 16 September 2026. Dates below describe the source or event; this is a local review edition.

React Server Components received a critical unauthenticated RCE fix.

What happened. The React team disclosed CVE-2025-55182, affecting several React Server DOM packages in versions 19.0, 19.1.0, 19.1.1 and 19.2.0. Patched versions were published with the advisory.

Impact and confidence

The affected package versions and impact are confirmed by the project. A React user interface by itself was not enough to establish exposure; server-component support and deployed dependency versions mattered.

Defensive takeaway

Check production dependency trees and framework guidance, then verify the deployed artifact uses a fixed package—not merely that a lockfile changed.

Evidence & dates

Follow the source.

Preserved from the earlier sourced news desk. This brief is distinct from the newly researched historical articles.

Source published
2025-12-03
Event date
2025-11-29
Site publication
Unpublished · local review
Critical Security Vulnerability in React Server Components
Make it useful

Turn the reading into a decision.

Open the interactive lab ↗
Search the evidence
Source image / inspection view

View original source ↗Local review · rights and provenance pending owner approval