Critical remote code execution (RCE) vulnerability

Release Date: 03rd of December 2025

Impact : HIGH / CRITICAL

TLP Rating: Clear

CERT Vanuatu (CERTVU) and the Department of Communication and Digital Transformation (DCDT) provide the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

 

  • CVE-2025-55182 (also dubbed “React2Shell”) is a critical remote-code-execution (RCE) vulnerability in React Server Components (RSC).
  • The vulnerability stems from unsafe deserialization of incoming HTTP request payloads in the “Flight” protocol handling RSC — malformed or malicious payloads can trigger arbitrary code execution on the server.

 

Read more

 

References

  1. https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/critical-vulnerability-in-react-server-components-cve-2025-55182
  2. https://www.cve.org/CVERecord?id=CVE-2025-55182