React Server Components Critical Vulnerability (CVE-2025-55182) Action Required
SDKs & Libraries

A pre-authentication remote code execution vulnerability (CVE-2025-55182) has been disclosed in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: 

 

  • React-server-dom-parcel
  • React-server-dom-turbopack
  • react-server-dom-webpack 

This vulnerability has been rated as a CVSS 10.0.

 

The vulnerability impacts all frameworks that support React Server Components, including Next.js and React Router.

 

Related Resource: See Okta’s Response to React2Shell

 

Immediate Action: Okta strongly advises that all developers who have built applications using Auth0 SDKs and sample libraries that require the vulnerable React libraries (see list below) should immediately update their applications to fixed versions of React (19.0.1, 19.1.2, and 19.2.1) and Next.js (fixed version list is available in the React blog post). 

 

Critical Notes:

  • Auth0 SDKs and sample libraries (list below) have been updated to require a fixed React version; users will see an error message if they attempt to use the SDK with an affected version of React.
  • The Okta SDKs (list below) are NOT affected as they do not depend on an affected version of React.
  • You must update to a fixed React library version. Updating only the SDK or sample library will not remediate this vulnerability.

 

Okta SDKs (no action required):

Auth0 Updated SDKs and Sample Libraries:

 

Recommended content

No recommended content found...