VORANT. Threat Intelligence Sign in Get the full feed

React Server Components RCE exploited in Japan

high vulnerability technology

A deserialization flaw in React Server Components (CVE-2025-55182), also affecting Next.js, is being actively exploited in Japan to achieve remote code execution.

IPA Japan issued an advisory warning that React Server Components, a server-side feature of the React JavaScript library, contains a vulnerability (CVE-2025-55182) allowing deserialization of untrusted data. Successful exploitation lets a remote attacker execute arbitrary code, and the flaw also impacts other products built on the same components, notably Next.js. On December 10, IPA updated the advisory to note that attacks believed to exploit this vulnerability have already occurred domestically, and warned that exploitation activity is likely to expand.

On December 12, three additional vulnerabilities were disclosed alongside the original issue: two denial-of-service flaws (CVE-2025-55184, CVE-2025-67779) and a source code exposure vulnerability (CVE-2025-55183). IPA recommends organizations address all four issues together and apply the patched versions released by the developers as soon as possible.

Given the confirmed in-the-wild exploitation of a remote code execution flaw in a widely deployed web framework component, organizations running React Server Components or Next.js should prioritize patching immediately. No specific indicators of compromise or attacker attribution have been publicly disclosed at this time.

Mentioned in this report

Vulnerabilities CVE-2025-55182KEVCVE-2025-55183CVE-2025-55184templatedCVE-2025-67779

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251209.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free