
12/3/2025 · Daniele Molteni
What this post added
This post details the deployment of new Web Application Firewall (WAF) rules to proactively protect against a Remote Code Execution (RCE) vulnerability in React Server Components (RSC) affecting React versions 19.0, 19.1, and 19.2, and Next.js versions 15 through 16. The new rules, identified by Rule ID 33aa8a8a948b48b28d40450c5fb92fba for the Managed Ruleset and 2b5d06e34a814a889bee9a0699702280 for the Free Ruleset, are deployed network-wide with a default 'Block' action. The post also notes that Cloudflare Workers are inherently immune to this exploit and recommends updating React and Next.js versions.