3 ms·
Dang, Cloudflare is moving fast. Cloudflare WAF proactively protects against React vulnerability https://blog.cloudflare.com/waf-rules-react-vulnerability/ http
by karimf 10mo ago
Dang, Cloudflare is moving fast. Cloudflare WAF proactively protects against React vulnerability https://blog.cloudflare.com/waf-rules-react-vulnerability/ https://blog.cloudflare.com/waf-rules-react-vulnerability/
- xnorswap 10mo agoThis is what coordinated disclosure looks like.
- karimf 10mo agoGiven that most Next.js and RSC apps run on Vercel, I’m wondering if they’re doing the same thing. There’s no information about this in their latest blog post [0]. Update: They do similar thing. Mentioned here [1] [0] https://nextjs.org/blog/CVE-2025-66478 https://nextjs.org/blog/CVE-2025-66478 [1] https://vercel.com/changelog/cve-2025-55182 https://vercel.com/changelog/cve-2025-55182
- bradly 10mo agoWould be interesting to hear from Cloudflare the extent of exploitation before today. I'm assuming they can see if/when this started being exploited.