CVE-2025-66478
- CVSS
- —
- EPSS
- —
- CISA KEV
- Not listed
- Exploitation
- No report
- Public exploits
- None seen
- State
- Unknown
Coverage
Vercel (blog + changelog)
New deployments of vulnerable Next.js applications are now blocked by default
CVE-2025-66478 Any new deployment containing a version of Next.js that is vulnerable towill now automatically fail to deploy on Vercel. Learn more We strongly recommend upgrading to a patched version regardless of your hosting provider. DANGEROUSLY_DEPLOY_VULNERABLE_CVE_2025_66478=1 Learn more This…
Actively exploitedCritical 95Vercel (blog + changelog)
Summary of CVE-2025-55182
See the for the latest updates. React2Shell security bulletin Summary Impact Resolution Credit References CVE-2025-55182 CVE-2025-66478 A critical-severity vulnerability in React Server Components () affects React 19 and frameworks that use it, including Next.js (). Under certain conditions…
What we observed
No signals recorded