React
fromArs Technica
3 weeks agoMaximum-severity vulnerability threatens 6% of all websites
An unsafe deserialization vulnerability in React Flight (CVE-2025-55182) enables unauthenticated remote code execution; upgrade patched React versions immediately.