10
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Description
CVE-2025-55182 Raw HTTP Requests to exploit the insecure lazy module load in react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0. Prerequisite: fs and module packages are loaded...
Basic Information
ID
5E9A6165-7807-5F02-A0F5-0DD3D2A951B3
Published
Dec 4, 2025 at 01:40
Modified
Dec 4, 2025 at 01:41