Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. next
  4. ›
  5. CVE-2025-66478

CVE-2025-66478: Next.js is vulnerable to RCE in React flight protocol

December 3, 2025 (updated December 4, 2025)

A vulnerability affects certain React packages1 for versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 and frameworks that use the affected packages, including Next.js 15.x and 16.x using the App Router. The issue is tracked upstream as CVE-2025-55182.

Fixed in: React: 19.0.1, 19.1.2, 19.2.1 Next.js: 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7

The vulnerability also affects experimental canary releases starting with 14.3.0-canary.77. Users on any of the 14.3 canary builds should either downgrade to a 14.x stable release or 14.3.0-canary.76.

All users of stable 15.x or 16.x Next.js versions should upgrade to a patched, stable version immediately.

1 The affected React packages are:

  • react-server-dom-parcel
  • react-server-dom-turbopack
  • react-server-dom-webpack

References

  • github.com/advisories/GHSA-9qr9-h5gf-34mp
  • github.com/vercel/next.js
  • github.com/vercel/next.js/security/advisories/GHSA-9qr9-h5gf-34mp
  • nvd.nist.gov/vuln/detail/CVE-2025-66478

Code Behaviors & Features

Detect and mitigate CVE-2025-66478 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 14.3.0-canary.77 before 15.0.5, all versions starting from 15.1.0-canary.0 before 15.1.9, all versions starting from 15.2.0-canary.0 before 15.2.6, all versions starting from 15.3.0-canary.0 before 15.3.6, all versions starting from 15.4.0-canary.0 before 15.4.8, all versions starting from 15.5.0-canary.0 before 15.5.7, all versions starting from 16.0.0-canary.0 before 16.0.7

Fixed versions

  • 15.0.5
  • 15.1.9
  • 15.2.6
  • 15.3.6
  • 15.4.8
  • 15.5.7
  • 16.0.7

Solution

Upgrade to versions 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7 or above.

Impact 10 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-502: Deserialization of Untrusted Data

Source file

npm/next/CVE-2025-66478.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sun, 14 Dec 2025 00:19:35 +0000.