Cybersecurity industry overreacts to React vulnerability, starts panic, burns own house down again
A few days ago, CVE-2025–55182 was revealed alongside an excellent write up: react.dev/blog/2025/12/03/critical-secu...lnerability-in-react-server-components The disclosure write up is great — it’s full of facts, and explains when you are and aren’t vulnerable. I don’t think anybody knows how to parse it and people have started taking actions before even knowing what they’re doing. To be vulnerable you have to be running: React v19 — released within the last year Using React Server Components —
评论
?
参与讨论