[GH-ISSUE #4921] Is netbird management dashboard affected by CVE-2025-55182? #10355

Open
opened 2026-08-05 01:25:35 -04:00 by saavagebueno · 0 comments
Owner

Originally created by @ChronSyn on GitHub (Dec 5, 2025).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/4921

Describe the problem

I received a notification that the management project may be vulnerable to CVE-2025-55182, and wanted to confirm if this is the case.

NIST: https://nvd.nist.gov/vuln/detail/CVE-2025-55182
Vercel: https://vercel.com/changelog/cve-2025-55182
React Dev: https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components

To Reproduce

Not applicable

Expected behavior

A response from the author/team whether the library is vulnerable, and if so, whether a patch is being prepared.
If possible, please identify which versions of the management dashboard are vulnerable (if any).

If vulnerable versions are identified, an update to be developed which includes an update to a version where the vulnerability is patched.

Are you using NetBird Cloud?

No - self-hosted

NetBird version

Not applicable - unsure, as the management dashboard doesn't list which version it is running, and the docker-compose file doesn't list the version either.

According to next in the browser dev console reports version 14.2.32.

Is any other VPN software installed?

No

Debug output

Not applicable

Screenshots

Not applicable

Additional context

None

Have you tried these troubleshooting steps?

  • Reviewed client troubleshooting (if applicable)
  • Checked for newer NetBird versions
  • Searched for similar issues on GitHub (including closed ones)
  • Restarted the NetBird client (N/A)
  • Disabled other VPN software (N/A)
  • Checked firewall settings (N/A)
Originally created by @ChronSyn on GitHub (Dec 5, 2025). Original GitHub issue: https://github.com/netbirdio/netbird/issues/4921 **Describe the problem** I received a notification that the management project may be vulnerable to CVE-2025-55182, and wanted to confirm if this is the case. NIST: https://nvd.nist.gov/vuln/detail/CVE-2025-55182 Vercel: https://vercel.com/changelog/cve-2025-55182 React Dev: https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components **To Reproduce** Not applicable **Expected behavior** A response from the author/team whether the library is vulnerable, and if so, whether a patch is being prepared. If possible, please identify which versions of the management dashboard are vulnerable (if any). If vulnerable versions are identified, an update to be developed which includes an update to a version where the vulnerability is patched. **Are you using NetBird Cloud?** No - self-hosted **NetBird version** Not applicable - unsure, as the management dashboard doesn't list which version it is running, and the docker-compose file doesn't list the version either. According to `next` in the browser dev console reports version `14.2.32`. **Is any other VPN software installed?** No **Debug output** Not applicable **Screenshots** Not applicable **Additional context** None **Have you tried these troubleshooting steps?** - [x] Reviewed [client troubleshooting](https://docs.netbird.io/how-to/troubleshooting-client) (if applicable) - [x] Checked for newer NetBird versions - [x] Searched for similar issues on GitHub (including closed ones) - [ ] Restarted the NetBird client (N/A) - [ ] Disabled other VPN software (N/A) - [ ] Checked firewall settings (N/A)
saavagebueno added the triage-needed label 2026-08-05 01:25:35 -04:00
Sign in to join this conversation.
No Label triage-needed
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#10355