Skip to main content
New Year’s Sale — Build a balanced news diet with 40% off Vantage
Published loading...Updated

Inside Vercel’s Sleep-Deprived Race to Contain React2Shell

Summary by CyberScoop
Talha Tariq and his colleagues at Vercel, the company that maintains Next.js, endured many sleep-deprived nights and weekends when React2Shell was discovered and disclosed soon after Thanksgiving. The defect, which affects vast stretches of the internet’s underlying infrastructure, posed a significant risk for Next.js, an open-source library that depends on vulnerable React Server Components. He quickly realized he had a major problem to confron…

3 Articles

At the beginning of December, the spectrum of a new Log4J was hovering on the React and Next.js apps with a critical flaw, the CVE-2025-55182. It was quickly called React4Shell. We were talking about it from December 4th: https://www.programz.com/actualites/react-et-nextjs-deux-failles-critiques-découvertes-jour-en-emergency-38655To sum up: These flaws allow you to execute distance code and weaken your default configuration. On React, they affec…

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

Programmez! broke the news in on Thursday, January 8, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal