pwnmyvibecode_

React vulnerabilities and security advisories

The newest reviewed advisories for react, react-dom, react-server-dom-webpack, react-server-dom-turbopack and react-server-dom-parcel on npm. Each one shows which versions are affected, which version fixes it, and a prompt that has your AI agent check your project and upgrade only if it needs to.

Get an email when React has a new one

Email alerts are coming soon. This page updates every hour.

$ latest 11 · 8 critical, high or exploited

  • highJul 24, 2026

    react-server-dom: Denial of Service in Server Functions

    • react-server-dom-webpack >= 19.0.0, < 19.0.8 · fixed in 19.0.8
    • react-server-dom-turbopack >= 19.0.0, < 19.0.8 · fixed in 19.0.8
    • react-server-dom-turbopack >= 19.1.0, < 19.1.9 · fixed in 19.1.9
    • react-server-dom-parcel >= 19.1.0, < 19.1.9 · fixed in 19.1.9
    • react-server-dom-webpack >= 19.1.0, < 19.1.9 · fixed in 19.1.9
    • react-server-dom-turbopack >= 19.2.0, < 19.2.8 · fixed in 19.2.8
    • react-server-dom-parcel >= 19.2.0, < 19.2.8 · fixed in 19.2.8
    • react-server-dom-webpack >= 19.2.0, < 19.2.8 · fixed in 19.2.8
    GHSA-wx67-qw84-cm4gCVE-2026-44907
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-wx67-qw84-cm4g (CVE-2026-44907), severity high
    What it is: react-server-dom: Denial of Service in Server Functions
    Affected packages:
    - react-server-dom-webpack: affected versions >= 19.0.0, < 19.0.8. Fixed in 19.0.8.
    - react-server-dom-turbopack: affected versions >= 19.0.0, < 19.0.8. Fixed in 19.0.8.
    - react-server-dom-turbopack: affected versions >= 19.1.0, < 19.1.9. Fixed in 19.1.9.
    - react-server-dom-parcel: affected versions >= 19.1.0, < 19.1.9. Fixed in 19.1.9.
    - react-server-dom-webpack: affected versions >= 19.1.0, < 19.1.9. Fixed in 19.1.9.
    - react-server-dom-turbopack: affected versions >= 19.2.0, < 19.2.8. Fixed in 19.2.8.
    - react-server-dom-parcel: affected versions >= 19.2.0, < 19.2.8. Fixed in 19.2.8.
    - react-server-dom-webpack: affected versions >= 19.2.0, < 19.2.8. Fixed in 19.2.8.
    Details: https://github.com/advisories/GHSA-wx67-qw84-cm4g
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highMay 11, 2026

    Facebook React has a Denial of Service Vulnerability in React Server Components

    • react-server-dom-parcel >= 19.0.0, < 19.0.6 · fixed in 19.0.6
    • react-server-dom-turbopack >= 19.0.0, < 19.0.6 · fixed in 19.0.6
    • react-server-dom-webpack >= 19.0.0, < 19.0.6 · fixed in 19.0.6
    • react-server-dom-parcel >= 19.1.0, < 19.1.7 · fixed in 19.1.7
    • react-server-dom-turbopack >= 19.1.0, < 19.1.7 · fixed in 19.1.7
    • react-server-dom-webpack >= 19.1.0, < 19.1.7 · fixed in 19.1.7
    • react-server-dom-parcel >= 19.2.0, < 19.2.6 · fixed in 19.2.6
    • react-server-dom-turbopack >= 19.2.0, < 19.2.6 · fixed in 19.2.6
    • react-server-dom-webpack >= 19.2.0, < 19.2.6 · fixed in 19.2.6
    GHSA-rv78-f8rc-xrxhCVE-2026-23870
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-rv78-f8rc-xrxh (CVE-2026-23870), severity high
    What it is: Facebook React has a Denial of Service Vulnerability in React Server Components
    Affected packages:
    - react-server-dom-parcel: affected versions >= 19.0.0, < 19.0.6. Fixed in 19.0.6.
    - react-server-dom-turbopack: affected versions >= 19.0.0, < 19.0.6. Fixed in 19.0.6.
    - react-server-dom-webpack: affected versions >= 19.0.0, < 19.0.6. Fixed in 19.0.6.
    - react-server-dom-parcel: affected versions >= 19.1.0, < 19.1.7. Fixed in 19.1.7.
    - react-server-dom-turbopack: affected versions >= 19.1.0, < 19.1.7. Fixed in 19.1.7.
    - react-server-dom-webpack: affected versions >= 19.1.0, < 19.1.7. Fixed in 19.1.7.
    - react-server-dom-parcel: affected versions >= 19.2.0, < 19.2.6. Fixed in 19.2.6.
    - react-server-dom-turbopack: affected versions >= 19.2.0, < 19.2.6. Fixed in 19.2.6.
    - react-server-dom-webpack: affected versions >= 19.2.0, < 19.2.6. Fixed in 19.2.6.
    Details: https://github.com/advisories/GHSA-rv78-f8rc-xrxh
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highApr 10, 2026

    React Server Components have a Denial of Service Vulnerability

    • react-server-dom-parcel >= 19.0.0, < 19.0.5 · fixed in 19.0.5
    • react-server-dom-parcel >= 19.1.0, < 19.1.6 · fixed in 19.1.6
    • react-server-dom-parcel >= 19.2.0, < 19.2.5 · fixed in 19.2.5
    • react-server-dom-turbopack >= 19.0.0, < 19.0.5 · fixed in 19.0.5
    • react-server-dom-turbopack >= 19.1.0, < 19.1.6 · fixed in 19.1.6
    • react-server-dom-turbopack >= 19.2.0, < 19.2.5 · fixed in 19.2.5
    • react-server-dom-webpack >= 19.0.0, < 19.0.5 · fixed in 19.0.5
    • react-server-dom-webpack >= 19.1.0, < 19.1.6 · fixed in 19.1.6
    • react-server-dom-webpack >= 19.2.0, < 19.2.5 · fixed in 19.2.5
    GHSA-479c-33wc-g2pgCVE-2026-23869
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-479c-33wc-g2pg (CVE-2026-23869), severity high
    What it is: React Server Components have a Denial of Service Vulnerability
    Affected packages:
    - react-server-dom-parcel: affected versions >= 19.0.0, < 19.0.5. Fixed in 19.0.5.
    - react-server-dom-parcel: affected versions >= 19.1.0, < 19.1.6. Fixed in 19.1.6.
    - react-server-dom-parcel: affected versions >= 19.2.0, < 19.2.5. Fixed in 19.2.5.
    - react-server-dom-turbopack: affected versions >= 19.0.0, < 19.0.5. Fixed in 19.0.5.
    - react-server-dom-turbopack: affected versions >= 19.1.0, < 19.1.6. Fixed in 19.1.6.
    - react-server-dom-turbopack: affected versions >= 19.2.0, < 19.2.5. Fixed in 19.2.5.
    - react-server-dom-webpack: affected versions >= 19.0.0, < 19.0.5. Fixed in 19.0.5.
    - react-server-dom-webpack: affected versions >= 19.1.0, < 19.1.6. Fixed in 19.1.6.
    - react-server-dom-webpack: affected versions >= 19.2.0, < 19.2.5. Fixed in 19.2.5.
    Details: https://github.com/advisories/GHSA-479c-33wc-g2pg
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highJan 29, 2026

    React Server Components have multiple Denial of Service Vulnerabilities

    • react-server-dom-parcel >= 19.0.0, < 19.0.4 · fixed in 19.0.4
    • react-server-dom-turbopack >= 19.1.0-canary-7130d0c6-20241212, < 19.1.5 · fixed in 19.1.5
    • react-server-dom-webpack >= 19.2.0-canary-63779030-20250328, < 19.2.4 · fixed in 19.2.4
    • react-server-dom-turbopack >= 19.0.0, < 19.0.4 · fixed in 19.0.4
    • react-server-dom-parcel >= 19.1.0-canary-7130d0c6-20241212, < 19.1.5 · fixed in 19.1.5
    • react-server-dom-parcel >= 19.2.0-canary-63779030-20250328, < 19.2.4 · fixed in 19.2.4
    • react-server-dom-webpack >= 19.1.0-canary-7130d0c6-20241212, < 19.1.5 · fixed in 19.1.5
    • react-server-dom-webpack >= 19.0.0, < 19.0.4 · fixed in 19.0.4
    • react-server-dom-turbopack >= 19.2.0-canary-63779030-20250328, < 19.2.4 · fixed in 19.2.4
    GHSA-83fc-fqcc-2hmgCVE-2026-23864
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-83fc-fqcc-2hmg (CVE-2026-23864), severity high
    What it is: React Server Components have multiple Denial of Service Vulnerabilities
    Affected packages:
    - react-server-dom-parcel: affected versions >= 19.0.0, < 19.0.4. Fixed in 19.0.4.
    - react-server-dom-turbopack: affected versions >= 19.1.0-canary-7130d0c6-20241212, < 19.1.5. Fixed in 19.1.5.
    - react-server-dom-webpack: affected versions >= 19.2.0-canary-63779030-20250328, < 19.2.4. Fixed in 19.2.4.
    - react-server-dom-turbopack: affected versions >= 19.0.0, < 19.0.4. Fixed in 19.0.4.
    - react-server-dom-parcel: affected versions >= 19.1.0-canary-7130d0c6-20241212, < 19.1.5. Fixed in 19.1.5.
    - react-server-dom-parcel: affected versions >= 19.2.0-canary-63779030-20250328, < 19.2.4. Fixed in 19.2.4.
    - react-server-dom-webpack: affected versions >= 19.1.0-canary-7130d0c6-20241212, < 19.1.5. Fixed in 19.1.5.
    - react-server-dom-webpack: affected versions >= 19.0.0, < 19.0.4. Fixed in 19.0.4.
    - react-server-dom-turbopack: affected versions >= 19.2.0-canary-63779030-20250328, < 19.2.4. Fixed in 19.2.4.
    Details: https://github.com/advisories/GHSA-83fc-fqcc-2hmg
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highDec 12, 2025

    Denial of Service Vulnerability in React Server Components

    • react-server-dom-parcel >= 19.0.2, < 19.0.3 · fixed in 19.0.3
    • react-server-dom-parcel >= 19.1.3, < 19.1.4 · fixed in 19.1.4
    • react-server-dom-parcel >= 19.2.2, < 19.2.3 · fixed in 19.2.3
    • react-server-dom-turbopack >= 19.0.2, < 19.0.3 · fixed in 19.0.3
    • react-server-dom-turbopack >= 19.1.3, < 19.1.4 · fixed in 19.1.4
    • react-server-dom-turbopack >= 19.2.2, < 19.2.3 · fixed in 19.2.3
    • react-server-dom-webpack >= 19.0.2, < 19.0.3 · fixed in 19.0.3
    • react-server-dom-webpack >= 19.1.3, < 19.1.4 · fixed in 19.1.4
    • react-server-dom-webpack >= 19.2.2, < 19.2.3 · fixed in 19.2.3
    GHSA-7gmr-mq3h-m5h9CVE-2025-67779
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-7gmr-mq3h-m5h9 (CVE-2025-67779), severity high
    What it is: Denial of Service Vulnerability in React Server Components
    Affected packages:
    - react-server-dom-parcel: affected versions >= 19.0.2, < 19.0.3. Fixed in 19.0.3.
    - react-server-dom-parcel: affected versions >= 19.1.3, < 19.1.4. Fixed in 19.1.4.
    - react-server-dom-parcel: affected versions >= 19.2.2, < 19.2.3. Fixed in 19.2.3.
    - react-server-dom-turbopack: affected versions >= 19.0.2, < 19.0.3. Fixed in 19.0.3.
    - react-server-dom-turbopack: affected versions >= 19.1.3, < 19.1.4. Fixed in 19.1.4.
    - react-server-dom-turbopack: affected versions >= 19.2.2, < 19.2.3. Fixed in 19.2.3.
    - react-server-dom-webpack: affected versions >= 19.0.2, < 19.0.3. Fixed in 19.0.3.
    - react-server-dom-webpack: affected versions >= 19.1.3, < 19.1.4. Fixed in 19.1.4.
    - react-server-dom-webpack: affected versions >= 19.2.2, < 19.2.3. Fixed in 19.2.3.
    Details: https://github.com/advisories/GHSA-7gmr-mq3h-m5h9
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highDec 11, 2025

    Denial of Service Vulnerability in React Server Components

    • react-server-dom-parcel >= 19.0.0, < 19.0.2 · fixed in 19.0.2
    • react-server-dom-turbopack >= 19.0.0, < 19.0.2 · fixed in 19.0.2
    • react-server-dom-webpack >= 19.0.0, < 19.0.2 · fixed in 19.0.2
    • react-server-dom-parcel >= 19.1.0, < 19.1.3 · fixed in 19.1.3
    • react-server-dom-parcel >= 19.2.0, < 19.2.2 · fixed in 19.2.2
    • react-server-dom-turbopack >= 19.1.0, < 19.1.3 · fixed in 19.1.3
    • react-server-dom-turbopack >= 19.2.0, < 19.2.2 · fixed in 19.2.2
    • react-server-dom-webpack >= 19.1.0, < 19.1.3 · fixed in 19.1.3
    • react-server-dom-webpack >= 19.2.0, < 19.2.2 · fixed in 19.2.2
    GHSA-2m3v-v2m8-q956CVE-2025-55184
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-2m3v-v2m8-q956 (CVE-2025-55184), severity high
    What it is: Denial of Service Vulnerability in React Server Components
    Affected packages:
    - react-server-dom-parcel: affected versions >= 19.0.0, < 19.0.2. Fixed in 19.0.2.
    - react-server-dom-turbopack: affected versions >= 19.0.0, < 19.0.2. Fixed in 19.0.2.
    - react-server-dom-webpack: affected versions >= 19.0.0, < 19.0.2. Fixed in 19.0.2.
    - react-server-dom-parcel: affected versions >= 19.1.0, < 19.1.3. Fixed in 19.1.3.
    - react-server-dom-parcel: affected versions >= 19.2.0, < 19.2.2. Fixed in 19.2.2.
    - react-server-dom-turbopack: affected versions >= 19.1.0, < 19.1.3. Fixed in 19.1.3.
    - react-server-dom-turbopack: affected versions >= 19.2.0, < 19.2.2. Fixed in 19.2.2.
    - react-server-dom-webpack: affected versions >= 19.1.0, < 19.1.3. Fixed in 19.1.3.
    - react-server-dom-webpack: affected versions >= 19.2.0, < 19.2.2. Fixed in 19.2.2.
    Details: https://github.com/advisories/GHSA-2m3v-v2m8-q956
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumDec 11, 2025

    Source Code Exposure Vulnerability in React Server Components

    • react-server-dom-parcel >= 19.0.0, < 19.0.2 · fixed in 19.0.2
    • react-server-dom-turbopack >= 19.0.0, < 19.0.2 · fixed in 19.0.2
    • react-server-dom-webpack >= 19.0.0, < 19.0.2 · fixed in 19.0.2
    • react-server-dom-parcel >= 19.1.0, < 19.1.3 · fixed in 19.1.3
    • react-server-dom-parcel >= 19.2.0, < 19.2.2 · fixed in 19.2.2
    • react-server-dom-turbopack >= 19.1.0, < 19.1.3 · fixed in 19.1.3
    • react-server-dom-turbopack >= 19.2.0, < 19.2.2 · fixed in 19.2.2
    • react-server-dom-webpack >= 19.1.0, < 19.1.3 · fixed in 19.1.3
    • react-server-dom-webpack >= 19.2.0, < 19.2.2 · fixed in 19.2.2
    GHSA-925w-6v3x-g4j4CVE-2025-55183
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-925w-6v3x-g4j4 (CVE-2025-55183), severity medium
    What it is: Source Code Exposure Vulnerability in React Server Components
    Affected packages:
    - react-server-dom-parcel: affected versions >= 19.0.0, < 19.0.2. Fixed in 19.0.2.
    - react-server-dom-turbopack: affected versions >= 19.0.0, < 19.0.2. Fixed in 19.0.2.
    - react-server-dom-webpack: affected versions >= 19.0.0, < 19.0.2. Fixed in 19.0.2.
    - react-server-dom-parcel: affected versions >= 19.1.0, < 19.1.3. Fixed in 19.1.3.
    - react-server-dom-parcel: affected versions >= 19.2.0, < 19.2.2. Fixed in 19.2.2.
    - react-server-dom-turbopack: affected versions >= 19.1.0, < 19.1.3. Fixed in 19.1.3.
    - react-server-dom-turbopack: affected versions >= 19.2.0, < 19.2.2. Fixed in 19.2.2.
    - react-server-dom-webpack: affected versions >= 19.1.0, < 19.1.3. Fixed in 19.1.3.
    - react-server-dom-webpack: affected versions >= 19.2.0, < 19.2.2. Fixed in 19.2.2.
    Details: https://github.com/advisories/GHSA-925w-6v3x-g4j4
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • criticalexploited in the wildDec 3, 2025

    React Server Components are Vulnerable to RCE

    • react-server-dom-webpack >= 19.1.0, < 19.1.2 · fixed in 19.1.2
    • react-server-dom-webpack = 19.2.0 · fixed in 19.2.1
    • react-server-dom-turbopack >= 19.1.0, < 19.1.2 · fixed in 19.1.2
    • react-server-dom-turbopack = 19.2.0 · fixed in 19.2.1
    • react-server-dom-parcel >= 19.1.0, < 19.1.2 · fixed in 19.1.2
    • react-server-dom-parcel = 19.2.0 · fixed in 19.2.1
    • react-server-dom-turbopack = 19.0.0 · fixed in 19.0.1
    • react-server-dom-parcel = 19.0.0 · fixed in 19.0.1
    • react-server-dom-webpack = 19.0.0 · fixed in 19.0.1
    GHSA-fv66-9v8q-g76rCVE-2025-55182
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-fv66-9v8q-g76r (CVE-2025-55182), severity critical
    What it is: React Server Components are Vulnerable to RCE
    CISA lists this as exploited in the wild, so treat it as urgent.
    Affected packages:
    - react-server-dom-webpack: affected versions >= 19.1.0, < 19.1.2. Fixed in 19.1.2.
    - react-server-dom-webpack: affected versions = 19.2.0. Fixed in 19.2.1.
    - react-server-dom-turbopack: affected versions >= 19.1.0, < 19.1.2. Fixed in 19.1.2.
    - react-server-dom-turbopack: affected versions = 19.2.0. Fixed in 19.2.1.
    - react-server-dom-parcel: affected versions >= 19.1.0, < 19.1.2. Fixed in 19.1.2.
    - react-server-dom-parcel: affected versions = 19.2.0. Fixed in 19.2.1.
    - react-server-dom-turbopack: affected versions = 19.0.0. Fixed in 19.0.1.
    - react-server-dom-parcel: affected versions = 19.0.0. Fixed in 19.0.1.
    - react-server-dom-webpack: affected versions = 19.0.0. Fixed in 19.0.1.
    Details: https://github.com/advisories/GHSA-fv66-9v8q-g76r
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumSep 4, 2020

    Cross-Site Scripting in react

    • react >= 0.4.0, < 0.4.2 · fixed in 0.4.2
    • react >= 0.5.0, < 0.5.2 · fixed in 0.5.2
    GHSA-g53w-52xc-2j85CVE-2013-7035
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-g53w-52xc-2j85 (CVE-2013-7035), severity medium
    What it is: Cross-Site Scripting in react
    Affected packages:
    - react: affected versions >= 0.4.0, < 0.4.2. Fixed in 0.4.2.
    - react: affected versions >= 0.5.0, < 0.5.2. Fixed in 0.5.2.
    Details: https://github.com/advisories/GHSA-g53w-52xc-2j85
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • highSep 4, 2020

    Cross-Site Scripting in react

    • react >= 0.0.1, < 0.14.0 · fixed in 0.14.0
    GHSA-hg79-j56m-fxgv
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-hg79-j56m-fxgv, severity high
    What it is: Cross-Site Scripting in react
    Affected packages:
    - react: affected versions >= 0.0.1, < 0.14.0. Fixed in 0.14.0.
    Details: https://github.com/advisories/GHSA-hg79-j56m-fxgv
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.
  • mediumJan 4, 2019

    Cross-Site Scripting in react-dom

    • react-dom = 16.0.0 · fixed in 16.0.1
    • react-dom >= 16.1.0, < 16.1.2 · fixed in 16.1.2
    • react-dom = 16.2.0 · fixed in 16.2.1
    • react-dom >= 16.3.0, < 16.3.3 · fixed in 16.3.3
    • react-dom >= 16.4.0, < 16.4.2 · fixed in 16.4.2
    GHSA-mvjj-gqq2-p4hwCVE-2018-6341
    prompt for your AI agent
    paste into your agent
    A security advisory covers a package this project may use.
    
    Advisory: GHSA-mvjj-gqq2-p4hw (CVE-2018-6341), severity medium
    What it is: Cross-Site Scripting in react-dom
    Affected packages:
    - react-dom: affected versions = 16.0.0. Fixed in 16.0.1.
    - react-dom: affected versions >= 16.1.0, < 16.1.2. Fixed in 16.1.2.
    - react-dom: affected versions = 16.2.0. Fixed in 16.2.1.
    - react-dom: affected versions >= 16.3.0, < 16.3.3. Fixed in 16.3.3.
    - react-dom: affected versions >= 16.4.0, < 16.4.2. Fixed in 16.4.2.
    Details: https://github.com/advisories/GHSA-mvjj-gqq2-p4hw
    
    Please:
    1. Check package.json and the lockfile (package-lock.json, pnpm-lock.yaml, yarn.lock or bun.lock) for these packages, including copies pulled in by other dependencies, and tell me which versions are installed.
    2. If none of them are installed, or every installed version is outside the affected ranges, say so and change nothing.
    3. If an installed version is affected, upgrade it to the fixed version for its release line or later. When the package only comes in through another dependency, upgrade that dependency, or add an override or resolution if it has no fixed release yet.
    4. If there is no fixed version, read the advisory and apply its workaround, or tell me the options.
    5. Reinstall, run the build and the tests, and fix anything the upgrade breaks.
    6. Tell me what you changed and which versions are installed now.

From the GitHub Advisory Database, refreshed hourly. Full history on GitHub.

Keeping React patched

  • npm audit (or pnpm audit) lists known vulnerable packages in your lockfile, including ones pulled in by other packages.
  • Turn on Dependabot for your GitHub repo and it opens the upgrade for you when an advisory lands.
  • A patched framework doesn't cover your own setup: headers, cookies and HTTPS. The free check looks at those.