The React Foundation has officially launched, hosted by the Linux Foundation. Read more here: react.dev/blog/2026/02...
The React Foundation has officially launched, hosted by the Linux Foundation. Read more here: react.dev/blog/2026/02...
We found that the fix to address the DoS vulnerability in React Server Components (CVE-2025-55184) was incomplete and does not prevent an attack in a specific case.
This is disclosed as CVE-2025-67779. New patches are available now, please update immediately.
These issues are present in the patches published last week for React2Shell. Even though they do not allow for Remote Code Execution they are high severity and you should update (again) immediately.
react.dev/blog/2025/12...
This pattern shows up across the industry, not just in JavaScript. For example, after Log4Shell, additional CVEs were reported as the community examined the original fix.
Additional disclosures can be frustrating, but they are generally a sign of a healthy response cycle.
It’s common for critical CVEs to uncover follow‑up vulnerabilities. When a critical vulnerability is disclosed, researchers scrutinize adjacent code paths looking for variant exploit techniques to test whether the initial mitigation can be bypassed.
We disclosed two new RSC vulnerabilities:
- Denial of Service (High): CVE-2025-55184
- Source Code Exposure (Medium): CVE-2025-55183
Patches are available now, please update immediately.
react.dev/blog/2025/12...
Researchers have found two new vulnerabilities in React Server Components while attempting to exploit the patches last week.
These are new issues, separate from the critical CVE last week. The patch for React2Shell remains effective for the Remote Code Execution exploit.
There is critical vulnerability in React Server Components disclosed as CVE-2025-55182 that impacts React 19 and frameworks that use it.
A fix has been published in React versions 19.0.1, 19.1.2, and 19.2.1. We recommend upgrading immediately.
react.dev/blog/2025/12...
There is critical vulnerability in React Server Components disclosed as CVE-2025-55182 that impacts React 19 and frameworks that use it.
A fix has been published in React versions 19.0.1, 19.1.2, and 19.2.1. We recommend upgrading immediately.
react.dev/blog/2025/12...
React Conf 2025 is a wrap! Check out the recap: react.dev/blog/2025/10...
Join the Discord to chat with fellow attendees and submit your questions for speakers to answer on the livestream: discord.gg/reactconf
Watch the livestream at conf.react.dev or YouTube www.youtube.com/watch?v=p9Oc...
React Conf Day 2 is starting now!
Introducing the React Foundation
Join the Discord to chat with fellow attendees and submit your questions for speakers to answer on the livestream: discord.gg/reactconf
Watch the livestream at conf.react.dev or YouTube www.youtube.com/watch?v=zyVR...
React Conf is starting now!
We are excited to announce @infinite.red, Old Mission, @arcjet.com, and @renderatl.com as React Conf silver sponsors this year!
We are excited to announce @mux.com as the React Conf livestream sponsor this year! Learn about how to build better video into websites, platforms, AI workflows, and more here: www.mux.com
We are excited to announce @redwoodjs.com as a React Conf Gold sponsor this year! Learn more about the React framework for Cloudflare here: rwsdk.com
We're excited to announce Gio Laquidara and Eric Fahsl as React Conf speakers! They'll be sharing how to use React and React Native to build for Amazon’s new Vega OS
Join the Discord to chat with fellow attendees and submit your questions for speakers to answer on the livestream: discord.gg/reactconf
Watch the livestream at conf.react.dev or YouTube www.youtube.com/watch?v=zyVR...
React Conf starts tomorrow!
Check out @dudak.me’s talk on how to craft great UX
We are excited to announce MUI as a React Conf Gold sponsor this year! Learn more about MUI’s suite of free UI tools here: mui.com
Check out James Swinton-Bland's talk to learn how to build an MCP Server for a React Component
We are excited to announce @ag-grid.bsky.social as a React Conf Gold sponsor this year! Learn how to add Data Grids to your application here: www.ag-grid.com