Skip to content

Conversation

@Vashiru
Copy link

@Vashiru Vashiru commented Dec 4, 2025

What are the changes and their implications?

NextJS and React have been updated to the latest patch releases within their respective minor versions to fix CVE-2025-66478 & CVE-2025-55182.

More info:

https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components

https://nextjs.org/blog/CVE-2025-66478

Bug Checklist

  • Changeset added (run pnpm changeset in the root directory)
  • Integration test added (see test docs if needed)

Feature Checklist

@changeset-bot
Copy link

changeset-bot bot commented Dec 4, 2025

🦋 Changeset detected

Latest commit: f9709ab

The changes in this PR will be included in the next version bump.

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@Vashiru
Copy link
Author

Vashiru commented Dec 12, 2025

@Vashiru Vashiru changed the title Fix CVE-2025-66478 & CVE-2025-55182 for React and Next.JS Fix CVE-2025-66478 & CVE-2025-55182 for React and Next.JS as well as CVE-2025-55184, CVE-2025-67779 and CVE-2025-55183 Dec 12, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants