Evidence dossier

CVE-2025-55182

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages:…

Exploited in the wild (CISA KEV since Dec 5, 2025). Meta reports CVSS 3.1 10.0. EPSS estimates 99.6% exploit likelihood as of Jul 31, 2026.

85.099.6Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

State
PUBLISHED
Published
Dec 3, 2025
Updated
Aug 4, 2026
Evidence coverage
85%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Meta React Server Components Remote Code Execution Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Meta React Server Components Remote Code Execution Vulnerability
    Original evidence ↗
  2. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 99.62% probability · 99.95th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.996160000000; percentile 0.999460000000
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  4. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  5. Source dateSource date omittedFirst observed by CASCA
    Meta

    Record text: A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

    Inspect raw assertion
    Field
    container
    Value
    A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Dec 5, 2025 · first observed Jul 19, 2026

Exploit likelihood99.62%

FIRST EPSS · score date Jul 31, 2026 · 99.9th percentile · first observed Aug 1, 2026

SeverityCVSS 10.0

Meta · CVSS 3.1 · first observed Aug 4, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

Outside this view’s verified evidence

Reason detail begins outside this selected snapshot; the state remains source-bound.

Source comparison

Who said what

CISA KEVOriginal assertion
Exploitation cataloged

Meta React Server Components Remote Code Execution Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Meta React Server Components Remote Code Execution Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

99.62% probability · 99.95th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.996160000000; percentile 0.999460000000
Source dateFirst observed by CASCAOriginal evidence ↗
CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
MetaOriginal assertion
Record text

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

Inspect raw assertion
Field
container
Value
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
82Underlying assertions
2Canonical products
82Target assertions
0Constraint assertions

Grouped from 2 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

5 scope groups

Meta · source assertedMetareact-server-dom-parcelDirect source scope
Affected: 19.0.0 through 19.0.0 (semver comparison)Affected: 19.1.0 through 19.1.1 (semver comparison)Affected: 19.2.0 through 19.2.0 (semver comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "19.0.0", "versionType": "semver", "lessThanOrEqual": "19.0.0"}, {"status": "affected", "version": "19.1.0", "versionType": "semver", "lessThanOrEqual": "19.1.1"}, {"status": "affected", "version": "19.2.0", "versionType": "semver", "lessThanOrEqual": "19.2.0"}]
Meta · source assertedMetareact-server-dom-turbopackDirect source scope
Affected: 19.0.0 through 19.0.0 (semver comparison)Affected: 19.1.0 through 19.1.1 (semver comparison)Affected: 19.2.0 through 19.2.0 (semver comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "19.0.0", "versionType": "semver", "lessThanOrEqual": "19.0.0"}, {"status": "affected", "version": "19.1.0", "versionType": "semver", "lessThanOrEqual": "19.1.1"}, {"status": "affected", "version": "19.2.0", "versionType": "semver", "lessThanOrEqual": "19.2.0"}]
Meta · source assertedMetareact-server-dom-webpackDirect source scope
Affected: 19.0.0 through 19.0.0 (semver comparison)Affected: 19.1.0 through 19.1.1 (semver comparison)Affected: 19.2.0 through 19.2.0 (semver comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "19.0.0", "versionType": "semver", "lessThanOrEqual": "19.0.0"}, {"status": "affected", "version": "19.1.0", "versionType": "semver", "lessThanOrEqual": "19.1.1"}, {"status": "affected", "version": "19.2.0", "versionType": "semver", "lessThanOrEqual": "19.2.0"}]
NVD CPE · APPLICATIONfacebookreactVulnerable target · 4 assertions
Version 19.0.0; Version 19.1.0; Version 19.1.1; Version 19.2.0Canonical identity product-801ad3088d7e34989779d23bc73a88d0a386b3efff90eddf9ed1d36152e206d6Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:facebook:react:19.2.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0030b5e1-e79e-4c48-b500-91747fe2751d
  2. cpe:2.3:a:facebook:react:19.1.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a0907e1c-e2d2-44a4-aa46-ce80bca4e015
  3. cpe:2.3:a:facebook:react:19.0.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c66e1b0f-8c3f-4d27-9f46-b6ec78d8c60b
  4. cpe:2.3:a:facebook:react:19.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c6c1c3e2-542d-4001-bfa9-6cf5a038971d
NVD CPE · APPLICATIONvercelnext.jsVulnerable target · 78 assertions
Any version (unconstrained) (>= 15.0.0, < 15.0.5); Any version (unconstrained) (>= 15.1.0, < 15.1.9); Any version (unconstrained) (>= 15.2.0, < 15.2.6); Any version (unconstrained) (>= 15.3.0, < 15.3.6); Any version (unconstrained) (>= 15.4.0, < 15.4.8); Any version (unconstrained) (>= 15.5.0, < 15.5.7); Any version (unconstrained) (>= 16.0.0, < 16.0.7); Version 14.3.0; Version 15.6.0; Version 16.0.0Canonical identity product-c6d89362417635b679b0855dfd0fa9fef30ef3da4c15e164bf449d2dee3a2333Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:vercel:next.js:15.6.0:canary15:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5d0b177b-2a31-48e9-81c7-1024e2452486
  2. cpe:2.3:a:vercel:next.js:15.6.0:canary45:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 59
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    00512630-8b88-43b0-9ed3-2b33c64cc9a9
  3. cpe:2.3:a:vercel:next.js:15.6.0:canary1:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    13b41c54-af21-4637-a852-f997635b4e83
  4. cpe:2.3:a:vercel:next.js:15.6.0:canary26:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 38
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    69142944-1ec0-4f94-862e-fa7f2e101101
  5. cpe:2.3:a:vercel:next.js:15.6.0:canary30:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 43
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e81c89fd-40cb-471e-9967-90acdcf79373
  6. cpe:2.3:a:vercel:next.js:15.6.0:-:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3ed7f693-8012-4f88-bc71-cf108e20664a
  7. cpe:2.3:a:vercel:next.js:15.6.0:canary39:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 52
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    53025212-05f0-41fe-81f8-023b1784bb8c
  8. cpe:2.3:a:vercel:next.js:14.3.0:canary78:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d1dcac23-7ed0-456b-8ae2-57689199f708
  9. cpe:2.3:a:vercel:next.js:15.6.0:canary46:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 60
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a88eef11-c7da-4e2d-a030-fc177e696557
  10. cpe:2.3:a:vercel:next.js:15.6.0:canary48:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 62
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e306b896-9bbb-424b-8d99-7a1a79aefe9d
  11. cpe:2.3:a:vercel:next.js:15.6.0:canary22:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ba4d4638-4734-4b16-87aa-ef4b5d2ddd7a
  12. cpe:2.3:a:vercel:next.js:15.6.0:canary52:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 67
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    984416ef-b121-40ce-b3ad-e22a06bb5844
  13. cpe:2.3:a:vercel:next.js:15.6.0:canary56:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 71
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e13cd688-63c3-4ffa-9d13-696005f0c155
  14. cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 6
    Logic
    OR
    Version bounds
    from including 16.0.0; through excluding 16.0.7
    Match ID
    cf65554e-4bf0-4344-ae7f-9e09e34e084f
  15. cpe:2.3:a:vercel:next.js:15.6.0:canary54:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 69
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8090cf73-aea7-43fc-a960-321bed3b1682
  16. cpe:2.3:a:vercel:next.js:15.6.0:canary14:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4f8fa85c-1200-4fd2-b5d7-906300748bd4
  17. cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 15.2.0; through excluding 15.2.6
    Match ID
    5efb6cb7-4a4f-464a-a1d8-62b50df0b4ba
  18. cpe:2.3:a:vercel:next.js:14.3.0:canary87:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c91f9508-e18d-4928-9df5-de2ddbec56d3
  19. cpe:2.3:a:vercel:next.js:14.3.0:canary83:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4828bee0-e891-491b-903d-a50b0e37273c
  20. cpe:2.3:a:vercel:next.js:15.6.0:canary53:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 68
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c4b58652-ee24-43cf-8abe-4a01b2c9938c
  21. cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 15.3.0; through excluding 15.3.6
    Match ID
    83af54d7-410d-42b4-853a-8a1973636542
  22. cpe:2.3:a:vercel:next.js:15.6.0:canary25:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 37
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    525efa40-b14b-47e9-8fbd-45721a802db6
  23. cpe:2.3:a:vercel:next.js:15.6.0:canary10:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    91b41697-2d70-488d-a5c3-cb9d435560ca
  24. cpe:2.3:a:vercel:next.js:15.6.0:canary21:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 33
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    389ee453-8b07-45dd-be9c-277c9c5cb156
  25. cpe:2.3:a:vercel:next.js:15.6.0:canary55:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 70
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    823164e5-609d-4f24-86a5-e25618fe86a7
  26. cpe:2.3:a:vercel:next.js:14.3.0:canary84:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    55723bb4-e62b-4034-a434-485fe0e6baf5
  27. cpe:2.3:a:vercel:next.js:15.6.0:canary40:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 54
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7411ef71-cbeb-4127-935f-3c732a1e22ac
  28. cpe:2.3:a:vercel:next.js:15.6.0:canary43:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 57
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    efe030a4-5b14-4c2d-b953-e80c98fb26ee
  29. cpe:2.3:a:vercel:next.js:14.3.0:canary85:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    19f55784-cc11-4024-9a42-efeef7b2366f
  30. cpe:2.3:a:vercel:next.js:15.6.0:canary38:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 51
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c151fdab-de34-4a7e-9762-6e99386798bf
  31. cpe:2.3:a:vercel:next.js:15.6.0:canary0:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    40ee98ac-754a-4fd9-b51a-9e2674584fd9
  32. cpe:2.3:a:vercel:next.js:15.6.0:canary35:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 48
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    48a82613-f3fd-4e89-8e4a-f3f05a616171
  33. cpe:2.3:a:vercel:next.js:15.6.0:canary12:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cec2346b-8dbd-4d53-9866-cfbdd3aacef2
  34. cpe:2.3:a:vercel:next.js:15.6.0:canary51:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 66
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fd397568-7f1f-4153-af08-b22d4d3b45f9
  35. cpe:2.3:a:vercel:next.js:14.3.0:canary82:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9eda2864-f94b-48eb-98f3-fdbfceccc4a8
  36. cpe:2.3:a:vercel:next.js:15.6.0:canary19:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e8440f05-f32b-4d40-90b7-04bf22107d86
  37. cpe:2.3:a:vercel:next.js:15.6.0:canary2:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fb6c6f6d-1ec0-4bd9-97a4-cfde70df0c43
  38. cpe:2.3:a:vercel:next.js:15.6.0:canary57:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 72
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b397b18c-8a7a-4766-9a68-98b26e190a4a
  39. cpe:2.3:a:vercel:next.js:15.6.0:canary47:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 61
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    be8453d9-7275-4a5f-8732-f05662fff2e8
  40. cpe:2.3:a:vercel:next.js:15.6.0:canary50:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 65
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7d7dccf7-fc83-4767-a0c2-c84a8b14f93b
  41. cpe:2.3:a:vercel:next.js:15.6.0:canary3:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 42
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3c907301-2c8f-465b-8134-94130e29f5db
  42. cpe:2.3:a:vercel:next.js:15.6.0:canary6:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 73
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2db345e3-bad0-497e-93ae-5e4dc669c192
  43. cpe:2.3:a:vercel:next.js:15.6.0:canary42:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 56
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b4977345-bd8c-41c7-9dd7-1e41d6cc6438
  44. cpe:2.3:a:vercel:next.js:15.6.0:canary17:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1ab351ae-8c29-4e67-8699-0aac6b3383e2
  45. cpe:2.3:a:vercel:next.js:15.6.0:canary7:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 74
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    840feb19-2c66-4004-a488-b90219f8ac05
  46. cpe:2.3:a:vercel:next.js:15.6.0:canary8:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 75
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c260f966-73d7-43f3-a329-8c558a695821
  47. cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 15.0.0; through excluding 15.0.5
    Match ID
    fc2bcd83-cc87-4cdc-ad9b-2055912a8463
  48. cpe:2.3:a:vercel:next.js:15.6.0:canary33:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 46
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7b27f133-8eb4-4761-a706-df42d4eb55f6
  49. cpe:2.3:a:vercel:next.js:15.6.0:canary31:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 44
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    55e8aeec-a686-49d6-b298-aee4e838e769
  50. cpe:2.3:a:vercel:next.js:15.6.0:canary20:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6189bd4c-a3e2-451b-96b2-ff01250e946d
  51. cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 15.1.0; through excluding 15.1.9
    Match ID
    c5e767d4-e46f-4ca6-a22f-4d0671b9b102
  52. cpe:2.3:a:vercel:next.js:15.6.0:canary34:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 47
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bf975472-b7e7-4ac8-b834-da19897a4894
  53. cpe:2.3:a:vercel:next.js:15.6.0:canary28:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 40
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e1536e2b-84ec-46a3-9b6f-026364a9d927
  54. cpe:2.3:a:vercel:next.js:14.3.0:canary79:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8b35d612-ac2a-4697-934f-372e4d5ee3f4
  55. cpe:2.3:a:vercel:next.js:15.6.0:canary18:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    14a34d9d-5fa2-434b-836e-3ce63d716ccb
  56. cpe:2.3:a:vercel:next.js:15.6.0:canary24:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 36
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e6136f0a-3010-4bad-811b-d047cf5e6f64
  57. cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 5
    Logic
    OR
    Version bounds
    from including 15.5.0; through excluding 15.5.7
    Match ID
    e666ecda-7a29-4d3d-ac40-357f044ad595
  58. cpe:2.3:a:vercel:next.js:15.6.0:canary16:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7cca01f3-3a14-4450-8a68-b1da22c685b7
  59. cpe:2.3:a:vercel:next.js:14.3.0:canary81:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8f01f07a-79f7-4f4b-8e3a-9c7d93c83a63
  60. cpe:2.3:a:vercel:next.js:15.6.0:canary41:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 55
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0c4b8930-1b65-4894-afa8-c323aa7a8292
  61. cpe:2.3:a:vercel:next.js:15.6.0:canary4:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 53
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    68eac2b9-32a5-4721-bb35-16d519cd1bbc
  62. cpe:2.3:a:vercel:next.js:15.6.0:canary5:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 64
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    77aa0d23-b101-445c-a260-ed3152a93d17
  63. cpe:2.3:a:vercel:next.js:15.6.0:canary29:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 41
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5e6f1f60-30e2-407c-8152-eeeb7efe24cb
  64. cpe:2.3:a:vercel:next.js:15.6.0:canary27:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 39
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    30016c06-372d-4f98-84a8-0732ca054970
  65. cpe:2.3:a:vercel:next.js:14.3.0:canary80:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a06d2291-5d89-4b76-99e0-52505634a63b
  66. cpe:2.3:a:vercel:next.js:15.6.0:canary37:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 50
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7c83a4ef-b96f-40ec-ba1f-fe1370af78ac
  67. cpe:2.3:a:vercel:next.js:15.6.0:canary44:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 58
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9f616fd4-83bf-4a9a-affd-0d3e2544dc7e
  68. cpe:2.3:a:vercel:next.js:16.0.0:-:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 77
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5e8548ab-d9e8-4e65-af24-9f9021f99834
  69. cpe:2.3:a:vercel:next.js:15.6.0:canary23:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d54a2e63-6e0c-4e17-86a8-459b0a7ee00b
  70. cpe:2.3:a:vercel:next.js:15.6.0:canary11:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7d43db84-7bcf-429b-849a-7189ec1922d0
  71. cpe:2.3:a:vercel:next.js:14.3.0:canary86:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1d694b0a-9bcf-49c8-a787-b0afe51c7dc5
  72. cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 15.4.0; through excluding 15.4.8
    Match ID
    3d666ea7-bdae-4e67-a331-b7403c3aa482
  73. cpe:2.3:a:vercel:next.js:15.6.0:canary36:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 49
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0d42ca1f-7c21-47c1-8a9c-1015286fcbe2
  74. cpe:2.3:a:vercel:next.js:14.3.0:canary77:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b209a306-ce1a-448d-8653-7627302399b7
  75. cpe:2.3:a:vercel:next.js:15.6.0:canary13:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2bc95097-8ca6-42fe-98d7-f968e37c11b7
  76. cpe:2.3:a:vercel:next.js:15.6.0:canary49:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 63
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    aca87b86-33d5-4bea-a13d-eeb4922d511e
  77. cpe:2.3:a:vercel:next.js:15.6.0:canary32:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 45
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cb0618ec-6a0b-4ac3-bf6d-e51ac84c4e15
  78. cpe:2.3:a:vercel:next.js:15.6.0:canary9:*:*:*:node.js:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 76
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    28130a79-39b5-43e8-a690-c8e9c62483f8

Affected-product evidence

Accepted scope and product mapping

0 canonical links · 0 source-reported links

Applicability remains source-scoped; safety and exposure remain unassessed.

Assessments

CVSS by origin

10.0
cve-assign@fb.comCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
10.0
MetaCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.