A critical severity vulnerability affecting server-side use of React.js, to be tracked as CVE-2026-XXXX.
This issue has been responsibly disclosed. Full details, affected versions, and advisories will be published here once the coordinated disclosure and patch process is complete.
Details to be announced. Watch this space.
Watch this space. We're giving people time to patch.
This website is maintained by an independent security researcher, and is not affiliated with Meta, the React team, or Vercel.