Trusted Design

CVE-2025-55182

  • 重大度: CRITICAL
  • 公開日: 2025-12-03
  • 更新日: 2026-02-26

概要

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

このCVEに関連するMITRE ATT&CKテクニック

このCVEが関連しているPulses

CVEの関係性グラフ


← CVE一覧に戻る