This pattern shows up across the industry.
For example, after Log4Shell, additional CVEs were reported as the community examined the original fix.
Additional disclosures can be frustrating, but they are generally a sign of a healthy response cycle.
It’s common for critical CVEs to uncover follow‑up vulnerabilities. When a critical vulnerability is disclosed, researchers scrutinize adjacent code paths looking for variant exploit techniques to test whether the initial mitigation can be bypassed.
We disclosed two new RSC vulnerabilities:
- Denial of Service (High): CVE-2025-55184
- Source Code Exposure (Medium): CVE-2025-55183
Patches are available now, please update immediately.
react.dev/blog/2025/12/11/de…
Researchers have found two new vulnerabilities in React Server Components while attempting to exploit the patches last week.
These are new issues, separate from the critical CVE last week. The patch for React2Shell remains effective for the Remote Code Execution exploit.
There is critical vulnerability in React Server Components disclosed as CVE-2025-55182 that impacts React 19 and frameworks that use it.
A fix has been published in React versions 19.0.1, 19.1.2, and 19.2.1. We recommend upgrading immediately.
react.dev/blog/2025/12/03/cr…
We're excited to announce @giolaq and @efahsl as React Conf speakers! They'll be sharing how to use React and React Native to build for Amazon’s new Vega OS