Front-end World

Front-end World

React Security: What Happened, What Was Affected, and What Comes Next

Kristiyan Velkov's avatar
Kristiyan Velkov
Dec 16, 2025
∙ Paid

In December 2025, React and Vercel disclosed two serious security vulnerabilities related to React Server Components, plus a third issue caused by an incomplete fix.

These issues don’t mean React is unsafe — but they do show that modern React.js apps now run real server logic, and server logic must be treated carefully. Let’s explain everything in plain words so everyone can understand it better.

User's avatar

Continue reading this post for free, courtesy of Kristiyan Velkov.

Or purchase a paid subscription.
© 2026 © 2025 Kristiyan Velkov. All rights reserved. · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture