ACTION REQUIRED: Review New vulnerability - React Server Components

IT Security.

A maximum severity vulnerability, dubbed ‘React2Shell’, in the React Server Components (RSC) ‘Flight’ protocol allows remote code execution without authentication in React and Next[.]js applications. The security issue stems from insecure deserialization. It received a severity score of 10/10 and has been assigned the identifiers CVE-2025-55182 for React and CVE-2025-66478 for Next[.]js.

What steps are being taken to mitigate these security vulnerabilities? Are you able to confirm these CVEs are being addressed in your environment?

Hi @Felipe2 , I will raise this internally and take a look right now.

Opened an inquiry with high priority (ZSEE-189560) and waiting to hear back. Will also have updated comms here: Zoom Security Bulletins | Zoom

Thanks so much!

Hi @Felipe2 ,

Confirmed across the security teams for Zoom services that we are not impacted by these CVEs. Our web-based services mostly use Vue, but those that contain some React are unaffected. Thank you!

Thanks for the clarification. It’s good to see that the issue was investigated with the security team and that the affected services were confirmed to be unaffected. Keeping the security bulletin updated is also helpful for customers who need to verify the status of these CVEs.