Website Security & Threat Management
Cloudflare WAF proactively protects against React vulnerability

Cloudflare WAF proactively protects against React vulnerability

12/3/2025 · Daniele Molteni

What this post added

This post details the deployment of new Web Application Firewall (WAF) rules to proactively protect against a Remote Code Execution (RCE) vulnerability in React Server Components (RSC) affecting React versions 19.0, 19.1, and 19.2, and Next.js versions 15 through 16. The new rules, identified by Rule ID 33aa8a8a948b48b28d40450c5fb92fba for the Managed Ruleset and 2b5d06e34a814a889bee9a0699702280 for the Free Ruleset, are deployed network-wide with a default 'Block' action. The post also notes that Cloudflare Workers are inherently immune to this exploit and recommends updating React and Next.js versions.

Read the original post ↗