• Web development
  • Next.js
  • Security

Next.js Security Update (Dec 11, 2025): What It Means for Your Application

The December 11, 2025 Next.js security update fixed React Server Components DoS and source code exposure bugs. Who is affected and which version to run.

By ZeroTwo SolutionsUpdated 3 min read

On December 11, 2025, the React and Next.js teams published a security update for vulnerabilities in React Server Components (RSC), the technology behind the Next.js App Router. It arrived only days after the critical “React2Shell” remote code execution fix, so many teams had just upgraded and now had to upgrade again. Here is what changed, who is affected and what to do.

What was fixed?

The update addressed two new vulnerabilities in the RSC protocol, plus a follow-up fix:

  • CVE-2025-55184: denial of service (high severity). A specially crafted HTTP request sent to a Server Function endpoint could make the server hang in an infinite loop and consume CPU, taking the application down.
  • CVE-2025-55183: source code exposure (medium severity). A crafted request could cause a Server Function to return the compiled source code of other Server Functions. Environment variables are not exposed this way, but any secrets hardcoded in source code could be.
  • CVE-2025-67779: incomplete fix follow-up. The first patches released on December 11 did not fully prevent the denial of service for every payload type, so a second round of patches followed later the same day.

Neither new issue allows remote code execution. However, the fixes for the earlier React2Shell vulnerability (CVE-2025-55182) do not cover them, so an application patched only for React2Shell is still exposed.

Who is affected?

Applications that use React Server Components, which in Next.js means the App Router, on these versions:

  • Next.js 13.4 and later 13.x releases with Server Actions enabled.
  • Next.js 14.x up to 14.2.34.
  • Next.js 15.x before the patched release for each minor line (for example, up to 15.5.8).
  • Next.js 16.x up to 16.0.9.

Applications that only use the Pages Router do not use React Server Components and are not affected by these specific issues, though upgrading is still good practice.

How to update

Upgrade to the fully patched release for your version line:

Your release line Upgrade to at least
13.x or 14.x 14.2.35
15.0.x 15.0.7
15.1.x 15.1.11
15.2.x 15.2.8
15.3.x 15.3.8
15.4.x 15.4.10
15.5.x 15.5.9
16.0.x 16.0.10

For example, on Next.js 16.0:

npm install next@16.0.10

If your project depends on React’s RSC packages directly (for example react-server-dom-webpack), update them to 19.0.3, 19.1.4 or 19.2.3 or later, matching your React minor version. After updating, run your test suite, deploy to staging first and check the Next.js changelog for anything that affects your app.

If you upgraded during the day on December 11, check that you are on the versions above and not on the first, incomplete round of patches.

What about hosting providers?

Some platforms deployed firewall rules to block known exploit patterns. That reduces exposure, but it is not a substitute for upgrading, especially for self-hosted deployments, where nothing sits between an attacker and your server unless you put it there.

Best practices going forward

  • Know exactly which version you run. Commit your lockfile and check the resolved next version in each deployed environment.
  • Automate dependency updates. Enable Dependabot or Renovate so security releases arrive as pull requests.
  • Watch the official advisories. Follow the Next.js blog and the GitHub security advisories for next and react.
  • Never hardcode secrets. Keep keys in environment variables or a secrets manager. CVE-2025-55183 is a reminder that source code can leak.
  • Rehearse fast upgrades. A staging environment and a reliable test suite let you ship a security patch in hours, not weeks.

Final thoughts

Security updates are not optional. Keeping dependencies current is one of the simplest and most effective ways to protect your users and your business. If you run the App Router, confirm you are on a fully patched version today.

More articles

All articles
Start a project

Have an AI or FinTech product to build?

Tell us what you want to ship. You will get a technical roadmap and a fixed-scope proposal within 48 hours.

  • Reply within 1 business day
  • NDA on request
  • You own 100% of the IP