TGViewer
DevOps community for love DevOps community for love @devopsforlove · 44.6K subscribers
Post #2849 478

Forwarded from Cult Of Wire

А тем временем в React и Next.js появились CVE c CVSS 10.0:
- CVE-2025-55182
- CVE-2025-66478 (на cve.org отмечена как REJECTED, duplicate of CVE-2025-55182)

Пошло довольно кучно: уязвимость затрагивает 19.0.0, 19.1.0, 19.1.1 и 19.2.0, а также фреймворки, использующие эти пакеты, включая Next.js 15.x и 16.x, использующие App Router.

Фиксы есть в версиях:
React: 19.0.1, 19.1.2, 19.2.1
Next.js: 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7

PoC пока не появился, но думаю, что можно ждать уже в ближайшее время.

UPD: PoC появился.

—
React Blog: Critical Security Vulnerability in React Server Components
Vercel: Summary of CVE-2025-55182
Github GitHub Advisory Database: Next.js is vulnerable to RCE in React flight protocol
GitHub RCE in React Server Components A vulnerability affects certain React packages<sup>1</sup> for versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 and frameworks that use the affected packages, including Next.js 15.x and 16.x...
  • 😱 1
More from @devopsforlove
  1. Oct 4, 2026Аудит безопасности Kubernetes-кластера без Kubernetes-кластера https://www.youtube.com/wat…
  2. Oct 3, 2026GitLab components. Как не докатиться до монолитных шаблонов CI/CD https://www.youtube.com/…
  3. Oct 2, 2026Пятничных вакансий пост) Сегодня у нас на завтрак DevSecOps Инженер по внедрению (DevSecOp…
  4. Oct 1, 2026Kubernetes без границ: Managed Kubernetes как вычислительный центр для ИИ https://habr.com…
  5. Sep 30, 2026Вход в Kubernetes по 2FA: как мы связали Gateway API, Dex и MULTIDIRECTORY https://habr.co…
  6. Sep 29, 2026Трагедия версионирования ПО https://habr.com/ru/companies/spring_aio/articles/1084716/ #de…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →