React Server Components RCE exploited in Japan
A deserialization flaw in React Server Components (CVE-2025-55182), also affecting Next.js, is being actively exploited in Japan to achieve remote code execution.
IPA Japan issued an advisory warning that React Server Components, a server-side feature of the React JavaScript library, contains a vulnerability (CVE-2025-55182) allowing deserialization of untrusted data. Successful exploitation lets a remote attacker execute arbitrary code, and the flaw also impacts other products built on the same components, notably Next.js. On December 10, IPA updated the advisory to note that attacks believed to exploit this vulnerability have already occurred domestically, and warned that exploitation activity is likely to expand.
On December 12, three additional vulnerabilities were disclosed alongside the original issue: two denial-of-service flaws (CVE-2025-55184, CVE-2025-67779) and a source code exposure vulnerability (CVE-2025-55183). IPA recommends organizations address all four issues together and apply the patched versions released by the developers as soon as possible.
Given the confirmed in-the-wild exploitation of a remote code execution flaw in a widely deployed web framework component, organizations running React Server Components or Next.js should prioritize patching immediately. No specific indicators of compromise or attacker attribution have been publicly disclosed at this time.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251209.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free