# Next.js Security Update: December 11, 2025

DevFeed: [Next.js Security Update: December 11, 2025](<https://devfeed.tech/articles/next-js-security-update-december-11-2025-3277.md>)

Original publisher: [Read original article](<https://nextjs.org/blog/security-update-2025-12-11>)

Author: Sebastian Markbåge

Published: 2025-12-11T16:00:00Z

Content type: news

Language: en

Sources: [Next.js Blog](<https://devfeed.tech/sources/next-js-blog.md>)

Topics: [Next.js](<https://devfeed.tech/topics/next-js.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [http](<https://devfeed.tech/tags/http.md>), [next-js](<https://devfeed.tech/tags/next-js.md>), [react](<https://devfeed.tech/tags/react.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

A Next.js security advisory describes two React Server Components vulnerabilities affecting App Router applications: a denial-of-service issue and potential compiled source-code exposure. Users are instructed to upgrade to the latest patched release, including those who applied the initial incomplete fix for CVE-2025-55184.

## Source excerpt

Two additional vulnerabilities have been identified in React Server Components. Users should upgrade to patched versions immediately.