Cloudflare WAF proactively protects against React vulnerability
blog.cloudflare.com·5d
☁️Cloudflare Workers
Preview
Report Post

2025-12-03

1 min read

Cloudflare has deployed a new protection to address a vulnerability in React Server Components (RSC). All Cloudflare customers are automatically protected, including those on free and paid plans, as long as their React application traffic is proxied through the Cloudflare Web Application Firewall (WAF).

Cloudflare Workers are inherently immune to this exploit. React-based applications and frameworks deployed on Workers are not affected by this vulnerability.

What you need to know

Cloudflare has been alerted by its security partners to a Remote Code Execution (RCE) vulnerability impacting Next.js, React Router, and othe…

Similar Posts

Loading similar posts...