Security Affairs newsletter Round 553 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-55182 | Unauthenticated RCE in React Server Components (React2Shell) CVE-2025-55182 is a critical (CVSS 10.0) pre-authentication remote code execution flaw (CWE-502, deserialization of untrusted data) in React Server Components, specifically the react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack packages in versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0. It is triggered when the vulnerable code unsafely deserializes payloads from HTTP requests sent to Server Function endpoints, requiring no authentication or user interaction. An attacker gains arbitrary code execution on the affected server (CVSS scope changed, with high impact to confidentiality, integrity, and availability), and reporting notes a campaign in which hackers used the flaw to breach 766 Next.js hosts and steal credentials. Any React/Next.js application exposing Server Functions with the affected React versions is in scope, which given the ubiquity of React and Next.js is a very large deployed base. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-05 with known ransomware use, EPSS puts the 30-day exploitation probability at 99.8%, multiple public PoC/scanner repositories are available, and coverage has dubbed the flaw React2Shell. Do: Upgrade the react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack packages to the vendor-patched releases (any version later than the vulnerable 19.0.0, 19.1.0, 19.1.1, and 19.2.0 line) and update Next.js per Vercel's advisory; as a KEV entry, U.S. federal agencies must apply vendor mitigations per BOD 22-01 or discontinue use. Audit internet-exposed Server Function endpoints for the vulnerable React versions and review logs for exploitation activity, including the reported campaign that breached 766 Next.js hosts and stole credentials, then rotate any exposed credentials. | 10.0 | 100% | KEV ransomware PoC ×7 |
| mass≈1M+ internet-facing Next.js/React Server Components deployments (order-of-magnitude estimate) | |
| CVE-2025-66516 | Critical XXE in Apache Tika PDF parsing via crafted XFA forms Apache Tika is vulnerable to XML External Entity (XXE) injection (CWE-611), rated critical at CVSS 9.8 (network-exploitable, no privileges or user interaction required), with the vulnerable code residing in tika-core but reachable through the PDF parser when it processes the XFA form embedded in a PDF. An attacker who can get Tika to parse a crafted PDF, typically by submitting a document to a Tika-based service or tika-server endpoint, can have the XML parser resolve external entities, gaining arbitrary local file read and SSRF from the Tika process, with CVSS impact rated high for confidentiality, integrity and availability. All platforms are affected across tika-core 1.13–3.2.1, tika-parser-pdf-module 2.0.0–3.2.1, and the 1.x tika-parsers module 1.13–1.28.5; notably the fix is in tika-core (3.2.2+), so upgrading only the PDF module leaves deployments vulnerable, and 1.x users need fixes in the tika-parsers module. Anyone running affected Tika versions to process untrusted PDFs is exposed, including standalone tika-server instances and downstream applications that embed Tika (vendors such as Atlassian have shipped fixes for embedded Tika). There is no CISA KEV listing and no public PoC or confirmed in-the-wild exploitation known, but EPSS puts it in the 100th percentile with an 80.3% probability of exploitation within 30 days. Do: Upgrade tika-core to 3.2.2 or later (upgrading only tika-parser-pdf-module is insufficient), and keep tika-parser-pdf-module aligned on the fixed 3.x line; users on the 1.x line should upgrade both tika-parsers and tika-core to the patched 1.x releases. If you consume Tika through another product (e.g., Solr-based stacks or Atlassian products), apply that vendor's patch. Until patched, avoid parsing untrusted PDFs with affected Tika versions, and restrict the Tika process's file-system and network access to limit file-read and SSRF impact. | 9.8 | 80% |
| mass≈100k+ exposed systems and plausibly millions of deployments/users (Tika is a ubiquitous Java document-parsing library bundled in Apache Solr, NiFi and… |
Full article397 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
December 07, 2025

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
Perth hacker Michael Clapsis jailed after setting up fake Qantas Wi-Fi, stealing sex videos
Europol and partners shut down ‘Cryptomixer’
Penn and Phoenix Universities Disclose Data Breach After Oracle Hack
ASUS confirms third-party breach as hackers release sample files
Russia blocks FaceTime and Snapchat for alleged use by terrorists
Malware
RadzaRat: New Android Trojan Disguised as File Manager Emerges with Zero Detection Rate
Chinese APT targets Uzbekistan
Malicious Rust Crate evm-units Serves Cross-Platform Payloads for Silent Execution
Hacking
Anatomy of a Hacktivist Attack: Russian-Aligned Group Targets OT/ICS
The Mystery OAST Host Behind a Regionally Focused Exploit Operation
Google Patches 107 Android Flaws, Including Two Framework Bugs Exploited in the Wild
Uncovering a Calendly-themed phishing campaign targeting business ad manager accounts
Attackers Actively Exploiting Critical Vulnerability in King Addons for Elementor Plugin
Array Networks Array AG Series vulnerable to command injection
A Hidden Pattern Within Months of Credential-Based Attacks Against Palo Alto GlobalProtect
Intelligence and Information Warfare
MuddyWater: Snakes by the riverbank
Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera
Intellexa Leaks: New Predator victims despite US sanctions
China-nexus cyber threat groups rapidly exploit React2Shell vulnerability (CVE-2025-55182)
Cybersecurity
Korean e-commerce behemoth Coupang confirms leak of 33.7 million users’ data
Facial Recognition’s Trust Problem
India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuse
Cloudflare’s 2025 Q3 DDoS threat report — including Aisuru, the apex of botnets
A New Anonymous Phone Carrier Lets You Sign Up With Nothing but a Zip Code
Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
Hundreds of Porsche Owners in Russia Unable to Start Cars After System Failure
NCSC Proactive Notifications Service
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
you might also like
leave a comment
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/185415/uncategorized/security-affairs-newsletter-round-553-by-pierluigi-paganini-international-edition.html