Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

React2Shell was a critical remote-code-execution flaw in React Server Components, rated CVSS 10.0 by the React team. Vercel says it coordinated on fixes before disclosure, then used web-application-firewall rules, runtime defenses and customer upgrade tools to reduce exposure. Those measures were temporary protection: Vercel’s guidance was to upgrade to a patched version. The official accounts document a rapid response, but do not establish how little named responders slept.

What React2Shell was—and why it affected more than server actions

React2Shell is the name commonly used for CVE-2025-55182, a vulnerability in React Server Components (RSC). The React team’s advisory rated it CVSS 10.0. A specially crafted request could reach server-side code evaluation and cause unintended remote code execution.

The important scope detail is that an application did not need to expose a React Server Function endpoint to be at risk: according to the React advisory, an app that supported React Server Components could still be vulnerable. That made the issue relevant to frameworks and deployments using RSC, not only to applications whose developers recognized that they had implemented server functions.

How the response unfolded

The sequence moved from private reporting and fix development to public disclosure, urgent mitigation and then a second wave of RSC security updates.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Date What happened
November 29, 2025 Researcher Lachlan Davidson reported the vulnerability to Meta’s bug bounty program.
November 30 Meta security researchers confirmed the issue and began working with the React team on a fix.
December 1 The React team says it created a fix and worked with affected hosting providers and open-source projects to validate it and roll out mitigations.
December 3 The fix was published to npm and the vulnerability was publicly disclosed as CVE-2025-55182.
December 4 Vercel’s security bulletin says public exploits emerged. The company’s guidance directed affected Next.js users to upgrade.
December 5–8 Vercel’s bulletin recorded an npm remediation tool announcement, a HackerOne bypass-research program, and advice about deployment protection and auditing shareable deployment links.
December 11 The React team disclosed additional RSC denial-of-service and source-code-exposure vulnerabilities.
December 19 Vercel published a retrospective on its researcher program, WAF updates, runtime defense and customer upgrade assistance.
January 26, 2026 React updated its follow-up advisory with additional patch guidance and fixed RSC package versions.

What Vercel did to reduce risk

Vercel describes a layered response: filter malicious traffic at the edge, add protection at the compute/runtime layer, alert customers to vulnerable deployments and make upgrades easier. These layers addressed different points in the attack path; neither should be confused with fixing the vulnerable application.

Measure What it was intended to do What it did not replace
WAF rules Filter known exploit patterns at the request layer. Vercel says it updated rules as new patterns appeared. A complete defense. Vercel warned that WAF rules cannot guarantee protection against every possible attack variant.
Runtime defense Vercel says a second mitigation operated at the compute/runtime level and was designed to block the code-evaluation vector. An application upgrade. The coverage figure Vercel reported for this layer is described below.
Customer notices and tooling Vercel says it used a security bulletin, dashboard banners for vulnerable deployments, the npx fix-react2shell-next CLI tool and automated pull requests through Vercel Agent to help customers act. The operator’s responsibility to deploy a patched version and verify the affected application was updated.

Why patching remained the decisive step

Vercel’s security bulletin put the distinction plainly: “Upgrading to a patched version is strongly recommended and the only complete fix.” Filtering and runtime controls can reduce exposure while teams respond, but a platform-side mitigation does not establish that an application’s vulnerable dependencies have been replaced.

  1. Identify what is deployed. Check the application’s dependency manifest and lockfile, and establish which Next.js and React Server Components packages and versions are actually used by the deployed build.
  2. Compare those versions with current official guidance. Vercel’s bulletin, last updated June 29, 2026, lists Next.js 15.0.0 through 16.0.6 and vulnerable Next.js 14 canaries after 14.3.0-canary.76 as affected by the original issue. Treat that as the bulletin’s stated scope, not a permanent substitute for checking the live advisory and package-specific upgrade instructions.
  3. Upgrade and deploy a fixed version. Use the current guidance for the framework and RSC packages in the project; the Vercel CLI remediation tool was also announced as an upgrade aid. Confirm that the patched build—not just a source change—has reached each relevant production deployment.
  4. Rotate secrets if the deployment was exposed and unpatched. Vercel advised rotation for exposed, unpatched deployments at the cutoff specified in its bulletin. Apply that guidance to the deployment’s actual exposure and follow the bulletin’s current instructions.

What Vercel’s response figures do—and do not—show

In its December 2025 retrospective and challenge announcement, Vercel reported the following operational figures. They are company-reported numbers; the cited official materials do not provide an independent audit of them.

  • Vercel said it blocked more than 6 million exploit attempts in the weeks after disclosure, including 2.3 million in a single 24-hour peak.
  • The company said 116 security researchers participated in finding WAF bypasses and that it paid more than $1 million through the challenge.
  • Vercel reported making 20 unique WAF updates in 48 hours.
  • Vercel said its runtime mitigation covered 96% of its traffic at the time of the retrospective.

These figures describe Vercel’s reported activity and coverage, not a guarantee that every deployment was protected or that every attack was blocked. Vercel’s own warning about WAF variants and its insistence on upgrading are the practical limits to keep in view.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The follow-up RSC flaws required more updates

The December 11 disclosures were not a claim that React2Shell’s initial fix had introduced remote code execution. The React team said the newly reported flaws did not allow RCE, but they included denial-of-service and source-code-exposure risks and still called for updates.

In an advisory updated January 26, 2026, React listed denial-of-service issues CVE-2025-55184, CVE-2025-67779 and CVE-2026-23864, each with a stated CVSS score of 7.5, plus source-code exposure CVE-2025-55183, scored 5.3. That advisory named fixed RSC package versions 19.0.4, 19.1.5 and 19.2.4. Those are the versions listed in that dated advisory, not a claim that they remain the latest releases; operators should use current package guidance when updating.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the “sleep-deprived” framing can support

The primary accounts establish an urgent, multi-stage security response and report substantial mitigation work. They do not quantify responders’ working hours or verify that particular people were sleep-deprived. Vercel CTO Malte Ubl’s retrospective captured the limit of platform defenses in one sentence: “But platform protections only buy time.” The documented takeaway is about coordinated mitigation followed by patching—not a verified account of anyone’s sleep.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.