logo

Cloudflare blames Friday outage on borked fix for React2shell vuln

ID: a68c270a-014d-5514-89e1-865edb0797a1

STIX ID: report--a68c270a-014d-5514-89e1-865edb0797a1

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2025-12-05

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

The report describes a critical CVE-2025-55182 ('React2Shell') unauthenticated RCE in React Server Components and related frameworks (including Next.js) that has a CVSS of 10.0; proof-of-concept exploits and both valid and fake PoCs proliferated rapidly after disclosure, multiple actors (including China-linked groups Earth Lamia and Jackpot Panda) have been observed scanning and attempting exploitation to steal AWS credentials and deploy downloaders, and the remediation effort even caused a significant Cloudflare outage while applying mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.