A critical vulnerability (CVE-2025-55182) was recently disclosed in React Server Components (RSC). A related issue (CVE-2025-66478) affects Next.js applications that use React 19 and Server Components.
According to the official advisory:
All Next.js v15 → v16 releases are affected.
Patched versions are: 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7
Other frameworks using RSC should update React to: 19.0.1, 19.1.2, or 19.2.1
I want to understand:
1. What exactly is this RSC vulnerability (CVE-2025-55182)?
2. Does it allow sensitive data exposure, server-side code execution, or RSC poisoning?
3. How severe is this for production Next.js apps?
4. Is it recommended to rotate environment variables/secrets after upgrading?
5. Is any manual code change required, or is upgrading sufficient?
Any official explanation, technical breakdown, or mitigation guidance would be very helpful.