The library for web and native user interfaces

Researchers have found two new vulnerabilities in React Server Components while attempting to exploit the patches last week. These are new issues, separate from the critical CVE last week. The patch for React2Shell remains effective for the Remote Code Execution exploit.
373
1,184
6,291
3,251,255
It’s common for critical CVEs to uncover follow‑up vulnerabilities. When a critical vulnerability is disclosed, researchers scrutinize adjacent code paths looking for variant exploit techniques to test whether the initial mitigation can be bypassed.
4
19
395
151,034
This pattern shows up across the industry. For example, after Log4Shell, additional CVEs were reported as the community examined the original fix. Additional disclosures can be frustrating, but they are generally a sign of a healthy response cycle.
1
23
304
121,041
There is critical vulnerability in React Server Components disclosed as CVE-2025-55182 that impacts React 19 and frameworks that use it. A fix has been published in React versions 19.0.1, 19.1.2, and 19.2.1. We recommend upgrading immediately. react.dev/blog/2025/12/03/cr…
166
1,019
3,921
2,586,992
We are excited to announce @infinite_red @OldMissionHQ @arcjet @RenderATL as React Conf silver sponsors this year!
4
11
98
26,010
We are excited to announce @MuxHQ as the React Conf livestream sponsor this year!
4
7
91
19,429
We are excited to announce @RedwoodJS as a React Conf Gold sponsor this year!
2
14
99
20,181
We're excited to announce @giolaq and @efahsl as React Conf speakers! They'll be sharing how to use React and React Native to build for Amazon’s new Vega OS
5
12
94
19,529