What are you looking for?
React2Shell Vulnerability
CVE-2025-55182 (React), CVE-2025-66478 (Next.js – later merged into CVE-2025-55182)
December 23, 2025
Overview
Keysight is aware of a vulnerability (CVE-2025-55182 (React), CVE-2025-66478 (Next.js – later merged into CVE-2025-55182) in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0. According to NIST, the vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
We have assessed the complete Keysight product portfolio available as of this time and determined that no products are impacted by the vulnerability1. Please note that some security tools may flag libraries or other components as potentially vulnerable to CVE-2025-66478 but Keysight has determined that these findings are false positives.
Impacted Products and Mitigation
None.
Recommended Action
In general, Keysight recommends that customers always update to the latest software versions available to them to safeguard against any vulnerabilities and threats.
For more information, please contact Keysight.
1 Keysight used commercially reasonable efforts to compile the list of products affected by the React2Shell vulnerability. Keysight offers this information for your convenience and does not warrant it is complete.
Want help or have questions?