Categories: Cyber Security News

644,000+ Domains at Risk Due to Critical React Server Components Flaw

A critical security vulnerability in React Server Components has left more than 644,000 domains and 165,000 IP addresses exposed to remote code execution attacks, according to updated scan data released by the Shadowserver Foundation on December 8, 2025.

Massive Internet-Wide Exposure Discovered

The vulnerability, tracked as CVE-2025-55182, was identified through an enhanced scan that revealed a large number of vulnerable systems across the internet.

The Shadowserver Foundation reported significant improvements in its scanning methodology, resulting in the discovery of numerous exposed systems.

The collaborative effort involved security research organizations Validin LLC and LeakIX, who worked alongside Shadowserver to identify and track the vulnerable installations.

The real-time statistics dashboard shows that the exposure affects a substantial portion of web infrastructure using React Server Components in production environments.

According to the React development team, CVE-2025-55182 represents an unauthenticated remote code execution vulnerability in React Server Components.

https://twitter.com/Shadowserver/status/1998427695982739671?ref_src=twsrc%5Etfw

This type of vulnerability is among the most severe security issues, as it allows attackers to execute arbitrary code on affected systems without requiring authentication credentials.

The React team has classified this as a critical security issue and has released emergency patches to address the vulnerability.

Fixed versions are now available in React 19.0.1, 19.1.2, and 19.2.1. The development team strongly recommends that all users running affected versions upgrade immediately to a patched release.

The severity of CVE-2025-55182 has prompted the Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities Catalog.

This designation indicates that the vulnerability is actively being exploited in the wild or poses a significant risk to federal enterprises and critical infrastructure.

Find this Story Interesting! Follow us on Google NewsLinkedIn and X to Get More Instant Update

The post 644,000+ Domains at Risk Due to Critical React Server Components Flaw appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Project Silent Whispers Takes Cinematic Adventure To The Next Level

Project Silent Whispers is giving romantic adventures a major upgrade. It’s a player-led romantic adventure…

2 hours ago

Katherine Legge Returns To Indy 500

SPEEDWAY, Ind. (WOWO) — Katherine Legge will be making her return to the Indianapolis 500…

2 hours ago

Indy East Side Shooting

INDIANAPOLIS, Ind. (WOWO) — A man was shot and killed on the east side of…

2 hours ago

Federal appeals court upholds Michael Madigan corruption convictions

The Seventh Circuit U.S. Court of Appeals issued its ruling Monday after hearing oral arguments…

2 hours ago

The CyberPowerPC RTX 5070 Gaming PC Drops to Just $1399 and Now Includes a Free Copy of Pragmata

Despite the rising prices of graphics cards and DDR5 RAM, there are still good deals…

3 hours ago

House of the Dragon Season 3 Trailer Breakdown: Expect Many Major Deaths Ahead

The new trailer for House of the Dragon Season 3 reveals Emma D’Arcy’s Queen Rhaenyra…

3 hours ago

This website uses cookies.