近期,聚铭安全攻防实验室监测发现了一项与React Server Components相关的远程代码执行漏洞, 该漏洞已被披露,编号为 CVE-2025-55182,CVSS 评分为 10.0 。
吴说获悉,慢雾首席信息安全官 23pds 发推表示,鉴于 React/Next.js 最新远程代码执行漏洞已出现新的攻击链,相关攻击成功率将显著提升。由于目前大量 DeFi 平台使用 React,该漏洞可能影响范围广泛,各 DeFi 平台需防范相关安全风险。
A maximum severity vulnerability, dubbed 'React2Shell', in the React Server Components (RSC) 'Flight' protocol allows remote ...
Researchers have uncovered a critical security flaw that could have catastrophic consequences for web and private cloud ...
Critical vulnerability in React library should be treated by IT as they did Log4j - as an emergency, warns one expert.
A critical RCE flaw in React.js, dubbed React2Shell (CVE-2025-55182), has been disclosed with a maximum CVSS score of 10.0, ...
11 月 29 日,Lachlan Davidson 报告了 React 中的一个安全漏洞,该漏洞允许通过利用 React 解码发送到 React Server Function 端点的有效负载的方式来 实现未经身份验证的远程代码执行 。
A newly discovered security flaw in the React ecosystem — one of the most widely used technologies on the web — is prompting ...
InfoQ中国 on MSN
Meta将把React迁移到Linux基金会
Meta将把React、React Native和JSX(JavaScript XML)贡献给一个新的React基金会,该基金会是Linux基金会的一部分,并表示“重要的是不要让任何一家公司或组织的代表过多。” ...
The Register on MSN
Beijing-linked hackers are hammering max-severity React bug, AWS warns
State-backed attackers started poking flaw as soon as it dropped – anyone still unpatched is on borrowed time Amazon has ...
A CVSS 10 rate critical vulnerability impacts React Server Components in versions 19.0–19.2.0. A patched update has been ...
一些您可能无法访问的结果已被隐去。
显示无法访问的结果