# ACTION REQUIRED: Review New vulnerability - React Server Components

**URL:** <https://devforum.zoom.us/t/action-required-review-new-vulnerability-react-server-components/139799>\
**Category:** Updates\
**Created:** [December 15, 2025, 6:01pm UTC](https://devforum.zoom.us/t/action-required-review-new-vulnerability-react-server-components/139799 "2025-12-15T18:01:28Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Felipe2](https://avatars.discourse-cdn.com/v4/letter/f/df705f/32.png) [@Felipe2](https://devforum.zoom.us/u/Felipe2)\
**Post date:** [December 15, 2025, 6:01pm UTC](https://devforum.zoom.us/t/action-required-review-new-vulnerability-react-server-components/139799/1 "2025-12-15T18:01:28Z")

</div>

IT Security.

A maximum severity vulnerability, dubbed ‘React2Shell’, in the React Server Components (RSC) ‘Flight’ protocol allows remote code execution without authentication in React and Next[.]js applications. The security issue stems from insecure deserialization. It received a severity score of **10/10** and has been assigned the identifiers CVE-2025-55182 for React and CVE-2025-66478 for Next[.]js.

What steps are being taken to mitigate these security vulnerabilities? Are you able to confirm these CVEs are being addressed in your environment?

---

<div class="post-metadata">

**Author:** ![gianni.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/gianni.zoom/32/32523_2.png) [@gianni.zoom](https://devforum.zoom.us/u/gianni.zoom)\
**Post date:** [December 17, 2025, 8:14pm UTC](https://devforum.zoom.us/t/action-required-review-new-vulnerability-react-server-components/139799/2 "2025-12-17T20:14:25Z")

</div>

Hi @Felipe2 , I will raise this internally and take a look right now.

---

<div class="post-metadata">

**Author:** ![gianni.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/gianni.zoom/32/32523_2.png) [@gianni.zoom](https://devforum.zoom.us/u/gianni.zoom)\
**Post date:** [December 17, 2025, 8:32pm UTC](https://devforum.zoom.us/t/action-required-review-new-vulnerability-react-server-components/139799/4 "2025-12-17T20:32:33Z")

</div>

Opened an inquiry with high priority (ZSEE-189560) and waiting to hear back. Will also have updated comms here: [Zoom Security Bulletins | Zoom](https://www.zoom.com/en/trust/security-bulletin/)

Thanks so much!

---

<div class="post-metadata">

**Author:** ![gianni.zoom](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/gianni.zoom/32/32523_2.png) [@gianni.zoom](https://devforum.zoom.us/u/gianni.zoom)\
**Post date:** [December 19, 2025, 3:30pm UTC](https://devforum.zoom.us/t/action-required-review-new-vulnerability-react-server-components/139799/5 "2025-12-19T15:30:27Z")

</div>

Hi @Felipe2 ,

Confirmed across the security teams for Zoom services that we are not impacted by these CVEs. Our web-based services mostly use Vue, but those that contain some React are unaffected. Thank you!

---

<div class="post-metadata">

**Author:** ![Raja](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/raja/32/50408_2.png) [@Raja](https://devforum.zoom.us/u/Raja)\
**Post date:** [August 28, 2026, 3:50am UTC](https://devforum.zoom.us/t/action-required-review-new-vulnerability-react-server-components/139799/7 "2026-08-28T03:50:03Z")

</div>

Thanks for the clarification. It’s good to see that the issue was investigated with the security team and that the affected services were confirmed to be unaffected. Keeping the security bulletin updated is also helpful for customers who need to verify the status of these CVEs.
