SecurityPatch Now: The React Server Components RCE (CVE-2025-55182) and the May 2026 13-CVE Release — A Version-by-Version Upgrade Map
CVE-2025-55182 is a CVSS 10.0 remote code execution flaw in the React Server Components deserialization path. If your app renders RSC payloads, you are exposed even without Server Functions. Here is the exact patched version for every react-server-dom line and Next.js release, plus WAF rules to buy time.
