Amid new reports of attackers pummeling a maximum security hole (CVE-2025-55182) in the React JavaScript library, Cloudflare's technology chief said his company took down its own network, forcing a widespread outage early Friday, to patch React2Shell. The network failure, which affected about 28 percent of HTTP traffic served by Cloudflare and caused websites around the world to go dark, "was not caused, directly or indirectly, by a cyber attack on Cloudflare's systems or malicious activity of any kind," said Cloudflare Chief Technical Officer Dane Knecht in a Friday blog. "Instead, it was triggered by changes being made to our body parsing logic while attempting to detect and mitigate an industry-wide vulnerability disclosed this week in React Server Components," he added. Cloudflare's snafu follows multiple reports from threat intel bods about attackers battering the critical React2Shell flaw, and several proof-of-concepts – some working, some fake – circulating on the internet, all of which started just hours after the bug was publicly disclosed. All of this illustrates the ubiquity of open source code powering the internet, and according to at least one threat-hunting exec, should encourage the security community to rethink the whole disclosure process. "Maybe we need to trust the security community and security providers more to act quickly and provide mitigations before threat actors are ready to exploit at a global scale," opined Radware VP of threat intel Pascal Geene...
Cloudflare blames Friday outage on borked fix for React2shell vuln
The Register
·Jessica Lyons
·Published Dec 5, 2025
·Updated
Affected Software
2 affected components
Meta React
Cloudflare React2Shell
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a security vulnerability in the React JavaScript library, specifically the React2Shell exploit, and its impact on Cloudflare's network.
2
What security implications are discussed?
The article highlights the significant risk associated with the CVE-2025-55182 vulnerability, which has been actively exploited by attackers.
3
What products or software are affected?
The affected software includes Meta React and the Cloudflare React2Shell implementation.
4
What caused the outage reported by Cloudflare?
Cloudflare experienced a widespread outage due to a problematic fix they implemented for the React2Shell vulnerability.
5
How are attackers exploiting the React2Shell vulnerability?
Reports indicate that attackers are leveraging the React2Shell vulnerability aggressively, exploiting systems that utilize the vulnerable React JavaScript library.