Created on
12-05-2025
09:18 AM
Edited on
12-11-2025
12:00 AM
By
Anthony_E
| Description |
This article describes FortiWeb and FortoAppSec protection for CVE-2025-55182.
On December 3, 2025, the React and Next.js teams disclosed a critical CVSS 10.0 security flaw, tracked as React2Shell (CVE-2025-55182), which impacts applications using React Server Components in combination with Server Actions or Server Functions. The issue arises from insufficient validation of untrusted client input in specific server-side React functionality, allowing an unauthenticated attacker to send crafted requests that can trigger unintended behavior on the server.
If exploited, this bug enables remote code execution without any prior authentication and poses a serious risk to many modern React and Next.js deployments that rely on these server capabilities. |
| Scope |
FortiWeb, FortiAppSec, CVE-2025-55182. |
| Solution |
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.