







I am very proud of the team for the runtime level mitigation we rolled out to @deno_land Deploy for this. It's very precise, very fast, and way less prone to false positives than the WAF based block. All versions of React are safe now when running on Deno Deploy - yay to vertical integration!
React
There is critical vulnerability in React Server Components disclosed as CVE-2025-55182 that impacts React 19 and frameworks that use it. A fix has been published in React versions 19.0.1, 19.1.2, and 19.2.1. We recommend upgrading immediately. react.dev/blog/2025/12/03/critical-secu…
Dec 3, 2025 at 4:51 PM
Web Without Walls — Dan Abramov | React Universe Conf 2024
Cloudflare WAF proactively protects against React vulnerability
Cloudflare offers protection against a new high profile vulnerability for React Server Components: CVE-2025-55182. All WAF customers are automatically protected as long as the WAF is deployed.

Critical Security Vulnerability in React Server Components
Discuss @tom.sherman.is's post on Frontpage.
Critical Security Vulnerability in React Server Components – React
The library for web and native user interfaces

GitHub - fatguru/CVE-2025-55182-scanner: A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications
A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications - fatguru/CVE-2025-55182-scanner
It's Svelte Time
When Svelte becomes a better choice for your frontend than React



claudio-silva/claude-artifact-runner
From Claude Artifact to deployable React app — in seconds!
State of React 2025
The 2025 edition of the annual survey about the latest trends in the React ecosystem.


Common Sense Refactoring of a Messy React Component | Alex Kondov
One thing I've learned from all the consulting I've done is that rewrites rarely lead to anything good. Almost in all cases, when you have an application runnin
GitHub - pmndrs/zustand: 🐻 Bear necessities for state management in React
🐻 Bear necessities for state management in React. Contribute to pmndrs/zustand development by creating an account on GitHub.

Next.js / React Server Components vulnerability identified. Apps deployed on Deno Deploy infrastructure are already protected by a runtime-level patch applied by our team. See this post for more information on how to protect your projects. deno.com/blog/react-server-functions-r…
React Server Functions / Next.js Vulnerability: Deno Deploy users protected | Deno
deno.comThere is critical vulnerability in React Server Components disclosed as CVE-2025-55182 that impacts React 19 and frameworks that use it. A fix has been published in React versions 19.0.1, 19.1.2, and 19.2.1. We recommend upgrading immediately. react.dev/blog/2025/12/03/critical-secu…
Critical Security Vulnerability in React Server Components – React
react.dev