# React Server Components RCE exploited in Japan

Published: 2025-12-11 · Severity: critical
Canonical: https://vorant.io/reports/64649ae9-cae9-5f86-899b-3b656e8aac2c/react-server-components-rce-exploited-in-japan

> Critical deserialization flaw CVE-2025-55182 in React Server Components enables remote code execution and is being actively exploited against Japanese targets.

Japan's IPA has issued an alert for a critical deserialization vulnerability (CVE-2025-55182) in React Server Components that allows remote attackers to execute arbitrary code. The vulnerability affects React and related frameworks including Next.js. According to the December 10th update, attacks exploiting this vulnerability have been observed domestically within Japan, prompting urgent calls for remediation.

The advisory was subsequently updated on December 12th to include three additional vulnerabilities discovered in React Server Components: two denial-of-service flaws (CVE-2025-55184, CVE-2025-67779) and a source code disclosure vulnerability (CVE-2025-55183). Organizations are advised to address all four vulnerabilities together when patching.

Developers have released patched versions across affected React releases. The IPA is urging immediate action given the confirmed exploitation and potential for widespread attacks against applications built on these widely-deployed JavaScript frameworks.

## Mentioned in this report

- Vulnerabilities: CVE-2025-55182 (KEV), CVE-2025-55183, CVE-2025-55184 (templated), CVE-2025-67779

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251209.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/64649ae9-cae9-5f86-899b-3b656e8aac2c/react-server-components-rce-exploited-in-japan.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
