TGViewer
AWS Notes AWS Notes @aws_notes · 5.82K subscribers
Post #3533 2.08K
AWS WAF vs CVE-2025-55182 (React2Shell)

https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/

CVE-2025-55182 - злобная уязвимость, при попытке раскатать защиту от которой, намедни прилёг CloudFlare.

Стоит поскорее обновить свои реактивные ресурсы.

В случае использования AWS WAF с дефолтным AWSManagedRulesKnownBadInputsRuleSet можно не переживать (но всё равно обновиться).

#security
Amazon China-nexus cyber threat groups rapidly exploit React2Shell vulnerability (CVE-2025-55182) | Amazon Web Services December 29, 2025: The blog post was updated to add options for AWS Network Firewall. December 12, 2025: The blog post was updated to clarify when customers need to update their ReactJS version. Within hours of the public disclosure of CVE-2025-55182 (React2Shell)…
  • ✍ 4
More from @aws_notes
  1. Sep 25, 2026Post #3689
  2. Sep 23, 2026Приглашаем на встречу Gnomish Factory: зачем я написал ещё одну Dark Factory Про тёмные фа…
  3. Sep 21, 2026🆕 Beanstalk + EKS Auto Mode = Beanstalk Cluster Mode 🎉 https://aws.amazon.com/blogs/aws/…
  4. Sep 20, 2026T8i — новое поколение burstable T-инстансов https://aws.amazon.com/blogs/aws/new-low-cost-…
  5. Sep 18, 2026Morning, people jan! We got some BIG news for students. 🥳 Time to get 12 Months of Skill…
  6. Sep 16, 2026Post #3684
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →