Skip to content

update dev dependencies to address cve#4200

Merged
huozhi merged 1 commit intovercel:mainfrom
PierreCrb:main
Dec 13, 2025
Merged

update dev dependencies to address cve#4200
huozhi merged 1 commit intovercel:mainfrom
PierreCrb:main

Conversation

@PierreCrb
Copy link
Copy Markdown
Contributor

React released an additional fix for an incomplete DoS patch (CVE-2025-67779).
Updated React to 19.0.3 / 19.2.3, as 19.0.2 / 19.2.2 are still vulnerable.

Next.js was also updated to include the patched React versions:

  • next: 16.0.9 → 16.0.10
  • react: 19.2.2 → 19.2.3
  • react-dom: 19.2.2 → 19.2.3

Refs:
https://x.com/reactjs/status/1999267418846449786

@codesandbox-ci
Copy link
Copy Markdown

This pull request is automatically built and testable in CodeSandbox.

To see build info of the built libraries, click here or the icon next to each commit SHA.

@huozhi huozhi changed the title fix: cve update dev dependencies to address cve Dec 13, 2025
@huozhi huozhi merged commit b2e7db3 into vercel:main Dec 13, 2025
6 checks passed
dcondrey pushed a commit to dcondrey/swr that referenced this pull request Dec 24, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants