Cloudflare blames Friday outage on borked fix for React2shell vuln
ID: a68c270a-014d-5514-89e1-865edb0797a1
STIX ID: report--a68c270a-014d-5514-89e1-865edb0797a1
Feed Name: The Register (Security)
The report describes a critical CVE-2025-55182 ('React2Shell') unauthenticated RCE in React Server Components and related frameworks (including Next.js) that has a CVSS of 10.0; proof-of-concept exploits and both valid and fake PoCs proliferated rapidly after disclosure, multiple actors (including China-linked groups Earth Lamia and Jackpot Panda) have been observed scanning and attempting exploitation to steal AWS credentials and deploy downloaders, and the remediation effort even caused a significant Cloudflare outage while applying mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
