<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>KB-2362 Information about the React Server Components, including Next.js (React2Shell, CVE-2025-55182 &amp; CVE-2025-66478)</title><link>https://community.appian.com/support/w/kb/3741/kb-2362-information-about-the-react-server-components-including-next-js-react2shell-cve-2025-55182-cve-2025-66478</link><description /><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>KB-2362 Information about the React Server Components, including Next.js (React2Shell, CVE-2025-55182 &amp; CVE-2025-66478)</title><link>https://community.appian.com/support/w/kb/3741/kb-2362-information-about-the-react-server-components-including-next-js-react2shell-cve-2025-55182-cve-2025-66478</link><pubDate>Fri, 05 Dec 2025 18:52:55 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:160151e3-b3f4-409f-803c-3380eef70ac2</guid><dc:creator>pauline.delacruz</dc:creator><comments>https://community.appian.com/support/w/kb/3741/kb-2362-information-about-the-react-server-components-including-next-js-react2shell-cve-2025-55182-cve-2025-66478#comments</comments><description>Current Revision posted to Appian Knowledge Base by pauline.delacruz on 12/5/2025 6:52:55 PM&lt;br /&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Overview:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;On 03-Dec-2025, two vulnerabilities were discovered related to the React Server Components that affect React 19 and the frameworks that use it, including Next.js. Applications using affected versions of the React Server Components implementation may process untrusted input in a way that allows an attacker to perform remote code execution.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-family:inherit;"&gt;Affected Components:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;React Server components in React 19.x and Next.js 15.x/16.x with App Router&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Appian has investigated these vulnerabilities and services, and determined that it is not impacted.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;While Appian is not vulnerable, if you have embedded Appian applications in other resources, those may be vulnerable. We encourage customers to check the vulnerability status of these systems.&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Additional Notes:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The following CVEs were released with additional information on the scope of the vulnerability:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;CVE-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0)&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66478"&gt;&lt;span style="font-weight:400;"&gt;CVE-2025-66478&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (Next.js vulnerability, current rejected by NVD)&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Supporting Documentation:&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/"&gt;&lt;span style="font-weight:400;"&gt;https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://vercel.com/changelog/cve-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;https://vercel.com/changelog/cve-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This article applies to all supported versions of Appian.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Last reviewed:&amp;nbsp;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;Dec 5, 2025&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: Security&lt;/div&gt;
</description></item><item><title>KB-2362 Information about the React Server Components, including Next.js (React2Shell, CVE-2025-55182 &amp; CVE-2025-66478)</title><link>https://community.appian.com/support/w/kb/3741/kb-2362-information-about-the-react-server-components-including-next-js-react2shell-cve-2025-55182-cve-2025-66478/revision/7</link><pubDate>Fri, 05 Dec 2025 16:53:20 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:160151e3-b3f4-409f-803c-3380eef70ac2</guid><dc:creator>pauline.delacruz</dc:creator><comments>https://community.appian.com/support/w/kb/3741/kb-2362-information-about-the-react-server-components-including-next-js-react2shell-cve-2025-55182-cve-2025-66478#comments</comments><description>Revision 7 posted to Appian Knowledge Base by pauline.delacruz on 12/5/2025 4:53:20 PM&lt;br /&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Overview:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;On 03-Dec-2025, two vulnerabilities were discovered related to the React Server Components that affect React 19 and the frameworks that use it, including Next.js. Applications using affected versions of the React Server Components implementation may process untrusted input in a way that allows an attacker to perform remote code execution.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-family:inherit;"&gt;Affected Components:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;React Server components in React 19.x and Next.js 15.x/16.x with App Router&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Appian has investigated these vulnerabilities and services, and determined that it is not impacted.&lt;/strong&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Additional Notes:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The following CVEs were released with additional information on the scope of the vulnerability:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;CVE-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0)&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66478"&gt;&lt;span style="font-weight:400;"&gt;CVE-2025-66478&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (Next.js vulnerability, current rejected by NVD)&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Supporting Documentation:&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/"&gt;&lt;span style="font-weight:400;"&gt;https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://vercel.com/changelog/cve-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;https://vercel.com/changelog/cve-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This article applies to all supported versions of Appian.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Last reviewed:&amp;nbsp;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;Dec 5, 2025&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: Security&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-1865] Information about the React Server Components, including Next.js (React2Shell, CVE-2025-55182 &amp; CVE-2025-66478)</title><link>https://community.appian.com/support/w/kb/3741/kb-2362-information-about-the-react-server-components-including-next-js-react2shell-cve-2025-55182-cve-2025-66478/revision/6</link><pubDate>Fri, 05 Dec 2025 16:51:59 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:160151e3-b3f4-409f-803c-3380eef70ac2</guid><dc:creator>pauline.delacruz</dc:creator><comments>https://community.appian.com/support/w/kb/3741/kb-2362-information-about-the-react-server-components-including-next-js-react2shell-cve-2025-55182-cve-2025-66478#comments</comments><description>Revision 6 posted to Appian Knowledge Base by pauline.delacruz on 12/5/2025 4:51:59 PM&lt;br /&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Overview:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;On 03-Dec-2025, two vulnerabilities were discovered related to the React Server Components that affect React 19 and the frameworks that use it, including Next.js. Applications using affected versions of the React Server Components implementation may process untrusted input in a way that allows an attacker to perform remote code execution.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-family:inherit;"&gt;Affected Components:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;React Server components in React 19.x and Next.js 15.x/16.x with App Router&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Appian has investigated these vulnerabilities and services, and determined that it is not impacted.&lt;/strong&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Additional Notes:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The following CVEs were released with additional information on the scope of the vulnerability:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;CVE-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0)&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66478"&gt;&lt;span style="font-weight:400;"&gt;CVE-2025-66478&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (Next.js vulnerability, current rejected by NVD)&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Supporting Documentation:&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/"&gt;&lt;span style="font-weight:400;"&gt;https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://vercel.com/changelog/cve-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;https://vercel.com/changelog/cve-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span&gt;Affected Versions&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This article applies to all supported versions of Appian.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Last reviewed:&amp;nbsp;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;Dec 5, 2025&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;

&lt;div style="font-size: 90%;"&gt;Tags: Security&lt;/div&gt;
</description></item><item><title>[DRAFT SUPP-1865] Information about the React Server Components, including Next.js (React2Shell, CVE-2025-55182 &amp; CVE-2025-66478)</title><link>https://community.appian.com/support/w/kb/3741/kb-2362-information-about-the-react-server-components-including-next-js-react2shell-cve-2025-55182-cve-2025-66478/revision/5</link><pubDate>Fri, 05 Dec 2025 16:46:35 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:160151e3-b3f4-409f-803c-3380eef70ac2</guid><dc:creator>dan.endean</dc:creator><comments>https://community.appian.com/support/w/kb/3741/kb-2362-information-about-the-react-server-components-including-next-js-react2shell-cve-2025-55182-cve-2025-66478#comments</comments><description>Revision 5 posted to Appian Knowledge Base by dan.endean on 12/5/2025 4:46:35 PM&lt;br /&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Overview:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;On 03-Dec-2025, two vulnerabilities were discovered related to the React Server Components that affect React 19 and the frameworks that use it, including Next.js. Applications using affected versions of the React Server Components implementation may process untrusted input in a way that allows an attacker to perform remote code execution.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;h2&gt;&lt;/h2&gt;
&lt;h2&gt;&lt;span style="font-family:inherit;"&gt;Affected Components:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;React Server components in React 19.x and Next.js 15.x/16.x with App Router&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Appian has investigated these vulnerabilities and services, and determined that it is not impacted.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Additional Notes:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The following CVEs were released with additional information on the scope of the vulnerability:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;CVE-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0)&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66478"&gt;&lt;span style="font-weight:400;"&gt;CVE-2025-66478&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (Next.js vulnerability, current rejected by NVD)&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Supporting Documentation:&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/"&gt;&lt;span style="font-weight:400;"&gt;https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://vercel.com/changelog/cve-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;https://vercel.com/changelog/cve-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This article applies to all supported versions of Appian.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;span style="font-weight:400;"&gt;Last reviewed:&amp;nbsp;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;Dec 5, 2025&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item><item><title>[NEW] KB-XXXX Information about the React Server Components, including Next.js (React2Shell, CVE-2025-55182 &amp; CVE-2025-66478)</title><link>https://community.appian.com/support/w/kb/3741/kb-2362-information-about-the-react-server-components-including-next-js-react2shell-cve-2025-55182-cve-2025-66478/revision/4</link><pubDate>Fri, 05 Dec 2025 16:45:16 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:160151e3-b3f4-409f-803c-3380eef70ac2</guid><dc:creator>dan.endean</dc:creator><comments>https://community.appian.com/support/w/kb/3741/kb-2362-information-about-the-react-server-components-including-next-js-react2shell-cve-2025-55182-cve-2025-66478#comments</comments><description>Revision 4 posted to Appian Knowledge Base by dan.endean on 12/5/2025 4:45:16 PM&lt;br /&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Overview:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;On 03-Dec-2025, two vulnerabilities were discovered related to the React Server Components that affect React 19 and the frameworks that use it, including Next.js. Applications using affected versions of the React Server Components implementation may process untrusted input in a way that allows an attacker to perform remote code execution.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;h2&gt;&lt;/h2&gt;
&lt;h2&gt;&lt;span style="font-family:inherit;"&gt;Affected Components:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;React Server components in React 19.x and Next.js 15.x/16.x with App Router&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Appian has investigated these vulnerabilities and services, and determined that it is not impacted.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Additional Notes:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The following CVEs were released with additional information on the scope of the vulnerability:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;CVE-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0)&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66478"&gt;&lt;span style="font-weight:400;"&gt;CVE-2025-66478&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (Next.js vulnerability, current rejected by NVD)&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Supporting Documentation:&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/"&gt;&lt;span style="font-weight:400;"&gt;https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://vercel.com/changelog/cve-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;https://vercel.com/changelog/cve-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This article applies to all supported versions of Appian.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;span style="font-weight:400;"&gt;Last reviewed:&amp;nbsp;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;Dec 5, 2025&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item><item><title>[NEW] KB-XXXX Information about the React Server Components, including Next.js (React2Shell, CVE-2025-55182 &amp; CVE-2025-66478)</title><link>https://community.appian.com/support/w/kb/3741/kb-2362-information-about-the-react-server-components-including-next-js-react2shell-cve-2025-55182-cve-2025-66478/revision/3</link><pubDate>Fri, 05 Dec 2025 16:44:08 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:160151e3-b3f4-409f-803c-3380eef70ac2</guid><dc:creator>dan.endean</dc:creator><comments>https://community.appian.com/support/w/kb/3741/kb-2362-information-about-the-react-server-components-including-next-js-react2shell-cve-2025-55182-cve-2025-66478#comments</comments><description>Revision 3 posted to Appian Knowledge Base by dan.endean on 12/5/2025 4:44:08 PM&lt;br /&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Overview:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;On 03-Dec-2025, two vulnerabilities were discovered related to the React Server Components that affect React 19 and the frameworks that use it, including Next.js. Applications using affected versions of the React Server Components implementation may process untrusted input in a way that allows an attacker to perform remote code execution.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;h2&gt;&lt;/h2&gt;
&lt;h2&gt;Affected Components:&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;React Server components in React 19.x and Next.js 15.x/16.x with App Router&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian has investigated these vulnerabilities and services, and determined that&lt;/span&gt;&lt;span style="font-weight:400;"&gt; it is not impacted.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Additional Notes:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The following CVEs were released with additional information on the scope of the vulnerability:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;CVE-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0)&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66478"&gt;&lt;span style="font-weight:400;"&gt;CVE-2025-66478&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (Next.js vulnerability, current rejected by NVD)&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Supporting Documentation:&lt;/span&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/"&gt;&lt;span style="font-weight:400;"&gt;https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://vercel.com/changelog/cve-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;https://vercel.com/changelog/cve-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This article applies to all supported versions of Appian.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;span style="font-weight:400;"&gt;Last reviewed:&amp;nbsp;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;Dec 5, 2025&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item><item><title>[NEW] KB-XXXX Information about the React Server Components, including Next.js (React2Shell, CVE-2025-55182 &amp; CVE-2025-66478)</title><link>https://community.appian.com/support/w/kb/3741/kb-2362-information-about-the-react-server-components-including-next-js-react2shell-cve-2025-55182-cve-2025-66478/revision/2</link><pubDate>Fri, 05 Dec 2025 16:42:30 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:160151e3-b3f4-409f-803c-3380eef70ac2</guid><dc:creator>dan.endean</dc:creator><comments>https://community.appian.com/support/w/kb/3741/kb-2362-information-about-the-react-server-components-including-next-js-react2shell-cve-2025-55182-cve-2025-66478#comments</comments><description>Revision 2 posted to Appian Knowledge Base by dan.endean on 12/5/2025 4:42:30 PM&lt;br /&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Overview&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;On 03-Dec-2025, two vulnerabilities were discovered related to the React Server Components that affect React 19 and the frameworks that use it, including Next.js. Applications using affected versions of the React Server Components implementation may process untrusted input in a way that allows an attacker to perform remote code execution.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;h2&gt;Affected components&lt;/h2&gt;
&lt;h3&gt;&lt;span style="font-size:inherit;"&gt;React Server components in React 19.x and Next.js 15.x/16.x with App Router&lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian has investigated these vulnerabilities and services, and determined that&lt;/span&gt;&lt;span style="font-weight:400;"&gt; it is not impacted.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Additional Notes:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The following CVEs were released with additional information on the scope of the vulnerability:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;CVE-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0)&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66478"&gt;&lt;span style="font-weight:400;"&gt;CVE-2025-66478&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (Next.js vulnerability, current rejected by NVD)&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Supporting Documentation:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/"&gt;&lt;span style="font-weight:400;"&gt;https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://vercel.com/changelog/cve-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;https://vercel.com/changelog/cve-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This article applies to all supported versions of Appian.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;span style="font-weight:400;"&gt;Last reviewed:&amp;nbsp;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;Dec 5, 2025&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item><item><title>[NEW] KB-XXXX Information about the React Server Components, including Next.js (React2Shell, CVE-2025-55182 &amp; CVE-2025-66478)</title><link>https://community.appian.com/support/w/kb/3741/kb-2362-information-about-the-react-server-components-including-next-js-react2shell-cve-2025-55182-cve-2025-66478/revision/1</link><pubDate>Fri, 05 Dec 2025 16:41:05 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:160151e3-b3f4-409f-803c-3380eef70ac2</guid><dc:creator>dan.endean</dc:creator><comments>https://community.appian.com/support/w/kb/3741/kb-2362-information-about-the-react-server-components-including-next-js-react2shell-cve-2025-55182-cve-2025-66478#comments</comments><description>Revision 1 posted to Appian Knowledge Base by dan.endean on 12/5/2025 4:41:05 PM&lt;br /&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;On 03-Dec-2025, two vulnerabilities were discovered related to the React Server Components that affect React 19 and the frameworks that use it, including Next.js. Applications using affected versions of the React Server Components implementation may process untrusted input in a way that allows an attacker to perform remote code execution.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Affected components: React Server components in React 19.x and Next.js 15.x/16.x with App Router&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Appian has investigated these vulnerabilities and services, and determined that&lt;/span&gt;&lt;span style="font-weight:400;"&gt; it is not impacted.&lt;/span&gt;&lt;/p&gt;
&lt;h2&gt;&lt;span style="font-weight:400;"&gt;Additional Notes:&lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;The following CVEs were released with additional information on the scope of the vulnerability:&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;CVE-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0)&lt;/span&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66478"&gt;&lt;span style="font-weight:400;"&gt;CVE-2025-66478&lt;/span&gt;&lt;/a&gt;&lt;span style="font-weight:400;"&gt; - (Next.js vulnerability, current rejected by NVD)&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;Supporting Documentation:&lt;/span&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/"&gt;&lt;span style="font-weight:400;"&gt;https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://vercel.com/changelog/cve-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;https://vercel.com/changelog/cve-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li style="font-weight:400;"&gt;&lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182"&gt;&lt;span style="font-weight:400;"&gt;https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-55182&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-weight:400;"&gt;This article applies to all supported versions of Appian.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;span style="font-weight:400;"&gt;Last reviewed:&amp;nbsp;&lt;/span&gt;&lt;span style="font-weight:400;"&gt;Dec 5, 2025&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;
</description></item></channel></rss>