13/12/2025
π¨ URGENT: New Critical Security Alert for React & Next.js Developers π¨
Following the React2Shell disclosure, security researchers have discovered TWO additional critical vulnerabilities in React Server Components that require immediate patching.
CVE-2025-55184 (High Severity - Denial of Service)
CVE-2025-55183 (Medium Severity - Source Code Exposure)
These affect:
β’ React versions 19.0.0 through 19.2.1
β’ Next.js versions 13.x through 16.x
β’ Any application using React Server Components
β οΈ Important: Even if you've already patched against React2Shell, you need to upgrade again - these are separate vulnerabilities requiring the latest patched versions.
I've just published a comprehensive security bulletin covering:
β
When to upgrade your application
β
Understanding both vulnerabilities in detail
β
Step-by-step upgrade instructions (automated, CLI, and manual methods)
β
Vercel security actions dashboard
β
Deployment protection best practices
β
How to upgrade other frameworks
The initial fix for CVE-2025-55184 was incomplete, resulting in CVE-2025-67779. Everyone must upgrade to the latest patched versions immediately.
Read the full security bulletin here: https://www.nexusbyte.com.au/blog/cve-2025-55184-55183-security-bulletin
Have questions or need help securing your applications? Feel free to reach out - we're here to help keep your systems safe.
hashtag hashtag hashtag hashtag hashtag hashtag hashtag hashtag hashtag hashtag