Why do I have a risk against client-side React?
You may have seen CVE-2025-55182 reported as a risk in your scan, this shows as being against React server components, which are server-side only. However, Next.js does bundle React with server components enabled by default, and therefore we can detect it. Hexiosec ASM identifies software components and versions on discovered websites and checks them daily against the CVEs published in NIST’s National Vulnerability Database, which already includes this CVE. You can read more about how ASM detects CVEs here.
React: This vulnerability affects React Server Components, which run entirely on the server. Server components are not exposed to the browser, so no external scanner — including ASM — can determine whether a website is using the vulnerable server-side feature. Client-side React (which is externally visible) does not provide any indication of whether Server Components are present. As a result, this particular vulnerability, when found for React, cannot be externally detected and will not show in Hexiosec ASM scan results.
Next.js: In contrast, we can identify the version of Next.js in use. If ASM detects a version affected by CVE-2025-55182, we will raise the associated risk in the platform.