Sunday, January 18, 2026
  • About Web3Wire
  • Web3Wire NFTs
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Media Network
  • RSS Feed
  • Contact Us
Web3Wire
No Result
View All Result
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
No Result
View All Result
Web3Wire
No Result
View All Result
Home Artificial Intelligence

Criminal IP Reveals Global React2Shell RCE Exposure Across React Server Components

December 12, 2025
in Artificial Intelligence, GlobeNewswire, Web3
Reading Time: 8 mins read
5
SHARES
244
VIEWS
Share on TwitterShare on LinkedInShare on Facebook

Criminal IP

TORRANCE, Calif., Dec. 12, 2025 (GLOBE NEWSWIRE) — In December 2025, the critical React Server Components (RSC) vulnerability known as React2Shell (CVE-2025-55182) was publicly disclosed, revealing a structural flaw that enables unauthenticated remote code execution (RCE) across the React ecosystem. As active scanning and exploitation attempts rapidly followed and the vulnerability was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, understanding real-world exposure became an urgent priority for organizations worldwide. Criminal IP, AI SPERA’s cyber threat intelligence platform, analyzed global RSC-enabled services to assess the scale of risk, identify exposed assets, and monitor attacker activity—providing critical visibility into how React2Shell is impacting production environments and how organizations can respond effectively 

React2Shell is not tied to a specific framework; rather, it stems from a structural weakness in the RSC feature that affects the broader React ecosystem. This article examines the technical foundation of React2Shell, the exposure landscape of services using RSC, observed attacker activity, and the defensive strategies organizations should adopt.

React2Shell Vulnerability Overview: A Structural Flaw Allowing RCE Without Authentication

CVE-2025-55182 is caused by a validation flaw in the deserialization process of the Flight protocol, which React Server Components use to exchange state between the server and client. An attacker can achieve RCE simply by sending a crafted payload to the Server Functions endpoint without authentication, and because a PoC is already publicly available, the vulnerability is highly susceptible to automated attacks.

The impact extends to all services that use RSC, and because frameworks such as Next.js, React Router RSC, Waku, Vite RSC Plugin, Parcel RSC Plugin, and RedwoodJS share the same underlying structure, the broader React ecosystem is collectively exposed.

The official patch is available in react-server-dom-* packages version 19.0.1 / 19.1.2 / 19.2.1 or later, and the vulnerability is rated CVSS 10.0, indicating critical severity.

Exposure Analysis of React2Shell-Affected Assets Using Criminal IP

React2Shell is difficult to detect using traditional product banners or HTML content alone. React-based services are designed so that RSC components are not externally exposed, and frameworks like Next.js, which vendor React modules internally, make it even harder to identify the underlying technology stack. As a result, simple banner-based detection methods cannot reliably determine whether RSC is enabled or whether a service is exposed to this vulnerability.

In real-world environments, the most reliable detection method is to identify systems based on their HTTP response headers, and servers with RSC enabled consistently exhibit the following values.

Criminal IP Search Query: “Vary: RSC, Next-Router-State-Tree” 

Users can detect RSC-enabled servers in the United States using Criminal IP by applying queries based on these header patterns.

Criminal IP Search Query: “Vary: RSC, Next-Router-State-Tree” country: “US” 

Criminal IP

According to the Criminal IP Asset Search results, the query “Vary: RSC, Next-Router-State-Tree” country: “US”  identified a total of 109,487 RSC-enabled assets. This header pattern indicates that RSC is active on these servers. While it does not mean that all of them are vulnerable, it is a critical indicator of the large-scale exposure surface that exists.

Criminal IP

When examining the analysis results for a specific asset in Criminal IP, the server was found to have ports 80 and 443 exposed externally, and its response headers, SSL certificate details, vulnerability list, and Exploit DB associations could all be reviewed in a single unified page. In this asset, indicators relevant to React2Shell were identified alongside other critical vulnerabilities, including CVE-2023-44487 (HTTP/2 Rapid Reset), which has been widely abused in large-scale DDoS attacks.

This demonstrates how Criminal IP Asset Search provides multiple analysis layers that help assess whether an environment is realistically exploitable by attackers.

Security Mitigation Strategies

1. Immediate Update of React-Related Packages

Organizations should immediately update all React-related packages to their latest patched releases. The react-server-dom-webpack package must be upgraded to version 19.0.1, 19.1.2, or 19.2.1, while react-server-dom-parcel and react-server-dom-turbopack should be updated to version 19.0.1 or later to ensure they are protected from the vulnerability.

2. Verify Patch Availability for Each Framework

React RSC is used across multiple frameworks, including Next.js, Vite, Parcel, and RedwoodJS. Notably, Next.js vendors RSC internally, meaning that updating React packages alone may not automatically apply the fix. Therefore, it is essential to review each framework’s official security advisories or release notes and upgrade to the version in which the vulnerability has been addressed.

3. Minimize External Exposure of RSC Endpoints

Whenever possible, restrict access using a reverse proxy, WAF or authentication gateway.

4. Leverage Criminal IP for Monitoring

  • Monitor exposure of RSC-related header
  • Detect scanning attempts based on TLS fingerprints
  • Automatically block malicious scanning IPs
  • Check for vulnerability presence and associated Exploit DB entries

The Analysis’ Conclusion

React2Shell (CVE-2025-55182) is a critical vulnerability affecting the most widely used React-based services across the web ecosystem. With low exploitation complexity and publicly available PoCs, active attacks are spreading rapidly.

According to Criminal IP analysis, approximately 110,000 RSC-enabled services in the United States are exposed, underscoring the substantial risk of widespread exploitation. In addition to applying patches, identifying exposed RSC services and conducting real-time monitoring are essential components of an effective React2Shell response strategy. Criminal IP provides one of the most effective tools for accurately mapping this attack surface and strengthening defensive measures.

In relation to this, users can refer to Next.js Middleware Vulnerability Allows Authentication Bypass: Over 520K Assets at Risk. 

About Criminal IP

Criminal IP is the flagship cyber threat intelligence platform developed by AI SPERA. The platform is used in more than 150 countries and provides comprehensive threat visibility through enterprise security solutions such as Criminal IP ASM and Criminal IP FDS.

Criminal IP continues to strengthen its global ecosystem through strategic partnerships with Cisco, VirusTotal and Quad9. The platform’s threat data is also available through major US data warehouse marketplaces including Amazon Web Services (AWS), Microsoft Azure and Snowflake. This expansion improves global access to high quality threat intelligence from Criminal IP.

Contact
Michael Sena
AI SPERA
support@aispera.com

Photos accompanying this announcement are available at
https://www.globenewswire.com/NewsRoom/AttachmentNg/0cb7fe71-829e-4981-b158-2ad54aff77f7
https://www.globenewswire.com/NewsRoom/AttachmentNg/d20f60c7-a268-4472-83fa-1fccde88993a
https://www.globenewswire.com/NewsRoom/AttachmentNg/ec62a656-527d-43fc-bf30-bf85ef28b814

About Web3Wire
Web3Wire – Information, news, press releases, events and research articles about Web3, Metaverse, Blockchain, Artificial Intelligence, Cryptocurrencies, Decentralized Finance, NFTs and Gaming.
Visit Web3Wire for Web3 News and Events, Block3Wire for the latest Blockchain news and Meta3Wire to stay updated with Metaverse News.

ShareTweet1ShareSendShare2
Previous Post

FrenchieGPT.ai Announces Official Launch of AI App for Dog Training & Puppy Care

Next Post

Verum Messenger: Artificial Intelligence, eSIM, and Complete Anonymity in One App

Related Posts

Digital Clinical Workspaces Market May See a Big Move | Major Giants Cerner, Allscripts, MEDITECH, Oracle Health

Digital Clinical Workspaces Market HTF MI recently introduced Global Digital Clinical Workspaces Market study with 143+ pages in-depth overview, describing about the Product / Industry Scope and elaborates market size (2025-2032). The market Study is segmented by key regions which is accelerating the marketization. At present, the market is developing...

Read moreDetails

Mobile Edge Computing Market to Reach US$ 3.1 Billion by 2030 | CAGR 26.3% | Asia-Pacific Leads with 38% Share | Key Players: Advantech, Johnson Controls, HPE, Huawei, Nokia, Juniper, SAGUNA, SMART

Mobile Edge Computing Mobile Edge Computing Market OverviewThe global mobile edge computing (MEC) market reached US$ 0.6 billion in 2022 and is projected to grow to US$ 3.1 billion by 2030, registering a CAGR of 26.3% during 2024-2031. Mobile edge computing is critical for applications requiring extremely low latency, including...

Read moreDetails

Global Semiconductor Silicon Wafer Market to Reach US$ 29.08 Billion by 2032, Driven by 300mm Wafer Expansion and Rising Demand from AI, Memory, and Logic Chips | QY Research

Market Summary -The global Semiconductor Silicon Wafer market was valued at US$ 17,020 million in 2025 and is projected to reach US$ 29,080 million by 2032, growing at a CAGR of 8.1% during the forecast period 2026-2032.According to QY Research, the newly released report titled "Global Semiconductor Silicon Wafer Market...

Read moreDetails

Topical Acne Clearing Treatment Market to Get an Explosive Growth | Major Giants L’Oréal ,AbbVie, Almirall

Topical Acne Clearing Treatment Market HTF MI just released the Global Topical Acne Clearing Treatment Market Study, a comprehensive analysis of the market that spans more than 143+ pages and describes the product and industry scope as well as the market prognosis and status for 2026-2033. The marketization process is...

Read moreDetails

Global CMOS Image Sensor Market to Reach US$ 43.38 Billion by 2032, Driven by Smartphone Imaging, Automotive Vision, and AI-Enabled Cameras | QY Research

Market Summary -The global CMOS Image Sensor (CIS) market was valued at US$ 22,660 million in 2025 and is projected to reach US$ 43,380 million by 2032, expanding at a robust CAGR of 9.9% during the forecast period 2026-2032.According to QY Research, the newly published report titled "Global CMOS Image...

Read moreDetails

NeuroDyne Drops: Sharp Mind, Enhanced Memory, and Lasting Focus – As Nature Intended, Ingredients

NEURODYNE DROPS INTRODUCED AS A COGNITIVE WELLNESS SUPPLEMENT SUPPORTING HEALTHY MEMORY, FOCUS, AND MENTAL CLARITY New York City, NY, Jan. 17, 2026 (GLOBE NEWSWIRE) -- A new cognitive wellness supplement titled NeuroDyne Drops has been formally announced and introduced to the consumer wellness market as interest in cognitive longevity, mental...

Read moreDetails

Optivell Officially Announced as a Vision Support Formula for Preventive Eye Wellness

New York City, NY, Jan. 17, 2026 (GLOBE NEWSWIRE) -- OPTIVELL INTRODUCED AS A NEW VISION SUPPORT FORMULA FOR MODERN DIGITAL LIFESTYLES Introduction to the Product Launch Optivell has been formally introduced to the wellness market as a nutritional supplement designed to support healthy vision and eye comfort in the...

Read moreDetails

Sugar Clean Drops: Top Blood Sugar Support Supplement for Metabolic Wellness and Energy Support

SUGAR CLEAN DROPS ANNOUNCED AS A NEW SUPPLEMENT SUPPORTING HEALTHY BLOOD SUGAR AND METABOLIC WELLNESS New York City, NY, Jan. 17, 2026 (GLOBE NEWSWIRE) -- A new nutritional supplement, Sugar Clean Drops, has been formally introduced to support adults seeking healthy blood sugar maintenance within the context of balanced lifestyle...

Read moreDetails

Radiation Detection, Monitoring and Safety Market to Reach $5.23 Bn by 2031, Driven by Healthcare Expansion and Security Applications

Radiation Detection, Monitoring and Safety Market Mordor Intelligence has published a new report on the Radiation Detection, Monitoring and Safety Market, offering a comprehensive analysis of trends, growth drivers, and future projections.Radiation Detection, Monitoring and Safety Market OverviewThe Radiation Detection, Monitoring, and Safety Market continues to gain steady attention as...

Read moreDetails

Curate Announces Integration with StaffMate Online to Connect Event Planning and Staffing

Curate and Staffmate are aligning planning and staffing workflows to support event teams from proposal through execution. Curate, an event operations platform for caterers, florists, and venues, announced an upcoming integration with Staffmate, a workforce management platform used by event teams nationwide. The integration connects event planning and staffing workflows,...

Read moreDetails
Web3Wire NFTs - The Web3 Collective

Web3Wire, $W3W Token and .w3w tld Whitepaper

Web3Wire, $W3W Token and .w3w tld Whitepaper

Claim your space in Web3 with .w3w Domain!

Web3Wire

Trending on Web3Wire

  • Unifying Blockchain Ecosystems: 2024 Guide to Cross-Chain Interoperability

    147 shares
    Share 59 Tweet 37
  • Top Cross-Chain DeFi Solutions to Watch by 2025

    75 shares
    Share 30 Tweet 19
  • Top 5 Wallets for Seamless Multi-Chain Trading in 2025

    75 shares
    Share 30 Tweet 19
  • Understanding Soulbound Tokens SBT Their Definition and Significance

    45 shares
    Share 18 Tweet 11
  • Discover 2025’s Top 5 Promising Low-Cap Crypto Gems

    88 shares
    Share 35 Tweet 22
Join our Web3Wire Community!

Our newsletters are only twice a month, reaching around 10000+ Blockchain Companies, 800 Web3 VCs, 600 Blockchain Journalists and Media Houses.


* We wont pass your details on to anyone else and we hate spam as much as you do. By clicking the signup button you agree to our Terms of Use and Privacy Policy.

Web3Wire Podcasts

Upcoming Events

There are currently no events.

Latest on Web3Wire

  • Digital Clinical Workspaces Market May See a Big Move | Major Giants Cerner, Allscripts, MEDITECH, Oracle Health
  • Mobile Edge Computing Market to Reach US$ 3.1 Billion by 2030 | CAGR 26.3% | Asia-Pacific Leads with 38% Share | Key Players: Advantech, Johnson Controls, HPE, Huawei, Nokia, Juniper, SAGUNA, SMART
  • Payroll4Construction Compiles Resource Article Following Big Beautiful Bill Changes
  • Global Semiconductor Silicon Wafer Market to Reach US$ 29.08 Billion by 2032, Driven by 300mm Wafer Expansion and Rising Demand from AI, Memory, and Logic Chips | QY Research
  • Topical Acne Clearing Treatment Market to Get an Explosive Growth | Major Giants L’Oréal ,AbbVie, Almirall

RSS Latest on Block3Wire

  • Covo Finance: Revolutionary Crypto Leverage Trading Platform
  • WorldStrides and HEX Announce Partnership to Offer High School and University Students Innovative Courses Designed to Improve Their Outlook in the Digital Age
  • Cathedra Bitcoin Announces Leasing of 2.5-MW Bitcoin Mining Facility
  • Global Web3 Payments Leader, Banxa, Announces Integration With Metis to Usher In Next Wave of Cryptocurrency Users
  • Dexalot Launches First Hybrid DeFi Subnet on Avalanche

RSS Latest on Meta3Wire

  • Thumbtack Honored as a 2023 Transform Awards Winner
  • Accenture Invests in Looking Glass to Accelerate Shift from 2D to 3D
  • MetatronAI.com Unveils Revolutionary AI-Chat Features and Interface Upgrades
  • Purely.website – Disruptive new platform combats rising web hosting costs
  • WEMADE and Metagravity Sign Strategic Alliance MOU to Collaborate on Blockchain Games for the Metaverse
Web3Wire

Web3Wire is your go-to source for the latest insights and updates in Web3, Metaverse, Blockchain, AI, Cryptocurrencies, DeFi, NFTs, and Gaming. We provide comprehensive coverage through news, press releases, event updates, and research articles, keeping you informed about the rapidly evolving digital world.

  • About Web3Wire
  • Web3Wire NFTs – The Web3 Collective
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Event Partners
  • Community Partners
  • Our Media Network
  • Media Kit
  • RSS Feeds
  • Contact Us

Whitepaper | Tokenomics

Crypto Coins

  • Top 10 Coins
  • Top 50 Coins
  • Top 100 Coins
  • All Coins – Marketcap
  • Crypto Coins Heatmap

Crypto Exchanges

  • Top 10 Exchanges
  • Top 50 Exchanges
  • Top 100 Exchanges
  • All Crypto Exchanges

Crypto Stocks

  • Blockchain Stocks
  • NFT Stocks
  • Metaverse Stocks
  • Artificial Intelligence Stocks

Media Portfolio: Block3Wire | Meta3Wire

Web3 Resources

  • Top Web3 and Crypto Youtube Channels
  • Latest Crypto News
  • Latest DeFi News
  • Latest Web3 News

Blockchain Resources

  • Blockchain and Web3 Resources
  • Decentralized Finance (DeFi) – Research Reports
  • All Crypto Whitepapers

Metaverse Resources

  • AR VR and Metaverse Resources
  • Metaverse Courses
Claim your space in Web3 with .w3w!
Top 50 Web3 Blogs and Websites
Web3Wire Podcast on Spotify Web3Wire Podcast on Amazon Music 
Web3Wire - Web3 and Blockchain - News, Events and Press Releases | Product Hunt
Web3Wire on Google News
  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • Sitemap
  • For Search Engines
  • Crypto Sitemap
  • Exchanges Sitemap

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Coins
    • Top 10 Cryptocurrencies
    • Top 50 Cryptocurrencies
    • Top 100 Cryptocurrencies
    • All Coins
  • Exchanges
    • Top 10 Cryptocurrency Exchanges
    • Top 50 Cryptocurrency Exchanges
    • Top 100 Cryptocurrency Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.