Skip to content

Conversation

@lacamera
Copy link
Contributor

This updates react and react-dom (and related packages) to
19.2.3 to mitigate a critical RCE vulnerability in RCS.

As far as I can tell this project is currently not affected by the vulnerability, but I think it would be best to update the versions anyway.

References:

@nginxproxymanagerci
Copy link

Docker Image for build 1 is available on DockerHub:

nginxproxymanager/nginx-proxy-manager-dev:pr-5084

Note

Ensure you backup your NPM instance before testing this image! Especially if there are database changes.
This is a different docker image namespace than the official image.

Warning

Changes and additions to DNS Providers require verification by at least 2 members of the community!

@krutoileshii
Copy link

Hopefully this gets merged soon

@jc21 jc21 merged commit 52fae6d into NginxProxyManager:develop Jan 13, 2026
1 check passed
@lacamera lacamera deleted the security/CVE-2025-55182 branch January 13, 2026 08:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

React CVE score 10.0!

4 participants