Database Management

Why DPA is not vulnerable to CVE-2025-55182 and CVE-2025-66478

This article explains why SolarWinds Database Performance Analyzer (DPA) is not vulnerable to CVE-2025-55182 and CVE-2025-66478, as DPA does not utilize React.

First published date

12/10/2025 4:41 PM

Last published date

12/10/2025 4:41 PM

Overview

In 2025, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2025-55182.

CVE-2025-66478 has been rejected as it is a duplicate of CVE-2025-55182.

Product section

Database Performance Analyzer

Cause

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

Resolution

The vulnerability described in this CVE affects numerous software companies, but it does not impact SolarWinds Database Performance Analyzer (DPA), as DPA does not utilize React.