Featured resource
2026 Tech Forecast
2026 Tech Forecast

Stay ahead of what’s next in tech with predictions from 1,500+ business leaders, insiders, and Pluralsight Authors.

Get these insights
  • Course

Breaking! React & Next.js Hit by CVSS 10.0 Bug

Learn how CVE-2025-55182 impacts React Server Components and Next.js. This episode shows you how to identify affected apps, patch the flaw, and protect your stack.

Beginner
11m

Created by Matthew Lloyd Davies and Michael Teske

Last Updated Dec 08, 2025

Course Thumbnail
  • Course

Breaking! React & Next.js Hit by CVSS 10.0 Bug

Learn how CVE-2025-55182 impacts React Server Components and Next.js. This episode shows you how to identify affected apps, patch the flaw, and protect your stack.

Beginner
11m

Created by Matthew Lloyd Davies and Michael Teske

Last Updated Dec 08, 2025

Get started today

Access this course and other top-rated tech content with one of our business plans.

Try this course for free

Access this course and other top-rated tech content with one of our individual plans.

This course is included in the libraries shown below:

  • Security
What you'll learn

React and Next.js sit at the core of many modern web applications, and increasingly they don’t just render UI, they handle routing, data access and server-side logic. React Server Components (RSC) and the Next.js App Router blur the line between “frontend” and “backend”, putting framework code directly in front of sensitive services and secrets. In December 2025, CVE-2025-55182 was disclosed: a critical flaw in RSC request/response handling that lets an unauthenticated attacker send crafted payloads and achieve remote code execution on affected servers. The issue carries a CVSS 10.0 rating, impacts multiple React server packages and popular frameworks including Next.js, and dramatically raises the stakes for internet-facing deployments. This episode moves quickly from RSC/App Router fundamentals to practical defense. You’ll see how the bug arises in the architecture, learn how to identify vulnerable stacks in real environments, and walk through patching, short-term containment and monitoring strategies. By the end, you’ll be ready to brief stakeholders clearly and help keep high-value web services online when this – or the next – framework-level zero-day lands.

Breaking! React & Next.js Hit by CVSS 10.0 Bug
Beginner
11m
Table of contents

About the author
Matthew Lloyd Davies - Pluralsight course - Breaking! React & Next.js Hit by CVSS 10.0 Bug
Matthew Lloyd Davies
40 courses 4.7 author rating 47 ratings

Matt has a degree in Chemical engineering and a PhD in mathematical chemistry. He is also a GIAC certified incident handler and penetration tester and has regulated cyber security in the UK civil nuclear sector for many years.

About the author
Michael Teske - Pluralsight course - Breaking! React & Next.js Hit by CVSS 10.0 Bug
Michael Teske
70 courses 4.5 author rating 888 ratings

Michael Teske is an Author Evangelist with Pluralsight helping people elevate their skills. He has 20+ years of experience in IT Ops, including 17 as an IT instructor at a community college.

Get started with Pluralsight