mirror of
https://github.com/reactjs/react.dev.git
synced 2026-02-21 19:31:57 +00:00
update nextjs instructions (#8197)
This commit is contained in:
@@ -62,10 +62,11 @@ An unauthenticated attacker could craft a malicious HTTP request to any Server F
|
||||
|
||||
These instructions have been updated to include the new vulnerabilities:
|
||||
|
||||
|
||||
- **Denial of Service - High Severity**: [CVE-2025-55184](https://www.cve.org/CVERecord?id=CVE-2025-55184) (CVSS 7.5)
|
||||
- **Source Code Exposure - Medium Severity**: [CVE-2025-55183](https://www.cve.org/CVERecord?id=CVE-2025-55183) (CVSS 5.3)
|
||||
|
||||
They also include the additional case found, patched, and disclosed as [CVE-2025-67779](https://www.cve.org/CVERecord?id=CVE-2025-67779).
|
||||
|
||||
See the [follow-up blog post](/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components) for more info.
|
||||
|
||||
</Note>
|
||||
|
||||
Reference in New Issue
Block a user