programming.dev
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Sosthène Guédon to ReactEnglish · 1 month ago

Lessons learned from React's RCE

sgued.fr

external-link
message-square
0
link
fedilink
  • cross-posted to:
  • javascript
3
external-link

Lessons learned from React's RCE

sgued.fr

Sosthène Guédon to ReactEnglish · 1 month ago
message-square
0
link
fedilink
  • cross-posted to:
  • javascript
In the last few weeks, 3 vulnerabilities where found in the React web application framework. The first one, a server-side remote code execution (CVE-2025-55182) is the worst a vulnerability can get for a web framework. The two other ones are a denial of service (CVE-2025-67779), and a source code exposure (CVE-2025-55183), much less dangerous, yet still impactful. There are already a lot of writeups published talking about how these vulnerabilities happened, but I didn't see much about being said about preventative measures that would have limited the damage. In this entry, I'll explore potential mitigations that could have been applied ahead of time to prevent these vulnerabilities or at least limit their severity.
alert-triangle
You must log in or # to comment.

React

react

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

A community for discussing anything related to the React UI framework and it’s ecosystem.

https://react.dev/

Wormhole

[email protected]

Icon base by Skoll under CC BY 3.0 with modifications to add a gradient

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 1 user / week
  • 16 users / month
  • 106 users / 6 months
  • 379 local subscribers
  • 1.27K subscribers
  • 81 Posts
  • 75 Comments
  • Modlog
  • mods:
  • Ategon
  • CUFTA22
  • Berserker
  • BE: 0.19.13
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org