<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:49:52 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-15156</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-15156</link>
      <description>bdu:2025-15156</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-15156</guid>
    </item>
    <item>
      <title>certfr-2025-ale-014 — **&lt;span class="important-content"&gt;[Mise à jour du 11 décembre 2025]&lt;/span&gt;**

Le CERT-FR a connaissance de multiples ex…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-ale-014</link>
      <description>certfr-2025-ale-014</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-ale-014</guid>
    </item>
    <item>
      <title>certfr-2025-avi-1131 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1131</link>
      <description>certfr-2025-avi-1131</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-1131</guid>
    </item>
    <item>
      <title>cisco-sa-react-flight-TYw32Ddb — Remote Code Execution Vulnerability in React and Next.js Frameworks: December 2025</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-react-flight-tyw32ddb</link>
      <description>&lt;p&gt;On December 3, 2025, the React team released a security advisory regarding a vulnerability, CVE-2025-55182, in the React server that could allow an unauthenticated, remote attacker to perform remote code execution on an affected device or system.&#13;
&#13;
For a description of this vulnerability, see the public React Security Advisory [&amp;#34;https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components&amp;#34;].&#13;
&#13;
Cisco&amp;#39;s standard practice is to update integrated third-party software components to later versions as they become available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;On December 3, 2025, the React team released a security advisory regarding a vulnerability, CVE-2025-55182, in the React server that could allow an unauthenticated, remote attacker to perform remote code execution on an affected device or system.&#13;
&#13;
For a description of this vulnerability, see the public React Security Advisory [&amp;#34;https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components&amp;#34;].&#13;
&#13;
Cisco&amp;#39;s standard practice is to update integrated third-party software components to later versions as they become available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-react-flight-tyw32ddb</guid>
    </item>
    <item>
      <title>cnvd-2025-29924</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2025-29924</link>
      <description>cnvd-2025-29924</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2025-29924</guid>
    </item>
    <item>
      <title>EUVD-2026-344008</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-344008</link>
      <description>EUVD-2026-344008</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-344008</guid>
    </item>
    <item>
      <title>fkie_cve-2025-55182</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-55182</link>
      <description>&lt;p&gt;A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-55182</guid>
    </item>
    <item>
      <title>GHSA-fv66-9v8q-g76r — React Server Components are Vulnerable to RCE</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fv66-9v8q-g76r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: react-server-dom-webpack, npm: react-server-dom-turbopack, npm: react-server-dom-parcel&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;There is an unauthenticated remote code execution vulnerability in React Server Components.&lt;/p&gt;
&lt;p&gt;We recommend upgrading immediately.&lt;/p&gt;
&lt;p&gt;The vulnerability is present in versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 of:
* [react-server-dom-webpack](https://www.npmjs.com/package/react-server-dom-webpack)
* [react-server-dom-parcel](https://www.npmjs.com/package/react-server-dom-parcel)
* [react-server-dom-turbopack](https://www.npmjs.com/package/react-server-dom-turbopack?activeTab=readme)&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;A fix was introduced in versions [19.0.1](https://github.com/facebook/react/releases/tag/v19.0.1), [19.1.2](https://github.com/facebook/react/releases/tag/v19.1.2), and [19.2.1](https://github.com/facebook/react/releases/tag/v19.2.1). If you are using any of the above packages please upgrade to any of the fixed versions immediately.&lt;/p&gt;
&lt;p&gt;If your app’s React code does not use a server, your app is not affected by this vulnerability. If your app does not use a framework, bundler, or bundler plugin that supports React Server Components, your app is not affected by this vulnerability.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;See the [blog post](https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components) for more information and upgrade instructions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: react-server-dom-webpack, npm: react-server-dom-turbopack, npm: react-server-dom-parcel&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;There is an unauthenticated remote code execution vulnerability in React Server Components.&lt;/p&gt;
&lt;p&gt;We recommend upgrading immediately.&lt;/p&gt;
&lt;p&gt;The vulnerability is present in versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 of:
* [react-server-dom-webpack](https://www.npmjs.com/package/react-server-dom-webpack)
* [react-server-dom-parcel](https://www.npmjs.com/package/react-server-dom-parcel)
* [react-server-dom-turbopack](https://www.npmjs.com/package/react-server-dom-turbopack?activeTab=readme)&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;A fix was introduced in versions [19.0.1](https://github.com/facebook/react/releases/tag/v19.0.1), [19.1.2](https://github.com/facebook/react/releases/tag/v19.1.2), and [19.2.1](https://github.com/facebook/react/releases/tag/v19.2.1). If you are using any of the above packages please upgrade to any of the fixed versions immediately.&lt;/p&gt;
&lt;p&gt;If your app’s React code does not use a server, your app is not affected by this vulnerability. If your app does not use a framework, bundler, or bundler plugin that supports React Server Components, your app is not affected by this vulnerability.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;See the [blog post](https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components) for more information and upgrade instructions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fv66-9v8q-g76r</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2738 — Vercel Next.js und React Server Components (React2Shell): Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2738</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Vercel Next.js und React ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Vercel Next.js und React ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2738</guid>
    </item>
  </channel>
</rss>
