What is React Server Components vulnerability CVE-2025-55182 and how does it affect Next.js?
21:46 03 Dec 2025

A critical vulnerability (CVE-2025-55182) was recently disclosed in React Server Components (RSC). A related issue (CVE-2025-66478) affects Next.js applications that use React 19 and Server Components.

According to the official advisory:

All Next.js v15 → v16 releases are affected.

Patched versions are: 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7

Other frameworks using RSC should update React to: 19.0.1, 19.1.2, or 19.2.1

I want to understand:

1. What exactly is this RSC vulnerability (CVE-2025-55182)?

2. Does it allow sensitive data exposure, server-side code execution, or RSC poisoning?

3. How severe is this for production Next.js apps?

4. Is it recommended to rotate environment variables/secrets after upgrading?

5. Is any manual code change required, or is upgrading sufficient?

Any official explanation, technical breakdown, or mitigation guidance would be very helpful.

reactjs next.js vercel