It never rains, but it pours: A security bug with a maximum severity rating is putting many of the worlds' servers at risk
Fixes are available, though 'organizations should patch urgently'.
It's been a grim few months for the world of servers, cloud services, and hyperscalers. With AWS going AWOL in October and Cloudflare doing its best impression of a yo-yo in recent weeks, it would be nice to have some good news to share about that technology sector. Alas, no, as it turns out that a very popular web app framework, used heavily in servers around the world, has been discovered to have a maximum severity security bug.
The software packages in question are React Server Components, and the developers issued a rather alarming statement about a critical security vulnerability earlier this week (via The Register and Wiz).
Specifically, the vulnerability "allows unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints." Translating this to something more understandable, it basically means somebody can use a remote web request of a server running React JavaScript or a React-based application framework, and ultimately run dodgy code to extract data, override systems, or what have you.
It's so bad that it has a maximum severity rating on the CVE database. Fortunately, React's developers created a fix almost immediately, although the somewhat restrained "We recommend upgrading immediately" suggestion might not be enough to prevent anyone from successfully exploiting the vulnerability.
That's because React, et al is used by vast swathes of the web that everyday folks know about. The Register writes that "Meta's Facebook and Instagram, Netflix, Airbnb, Shopify, Hello Fresh, Walmart, and Asana rely on it." If you're a heavy user of Meta's apps, you should know that React is developed by it, so I think it's safe to assume that all its servers have already been patched.
The same can't be said for everyone else, though, especially if The Register's statement that an estimated 39% of all cloud environments have the vulnerability is true. Even if it's nowhere near this amount, it's still a significant portion of the web that is used on a daily basis, so I wouldn't be in the least bit surprised if I'm writing about another mass data breach on a server using React at some point in the near future.
There's a very popular XKCD image that accurately describes the entirety of the interwebs. When it all works, it's nothing short of a modern miracle, but if one tiny thing goes wrong, then the whole thing comes crashing down. Cloudflare's big shutdown in November was caused by a configuration file that simply "grew beyond an expected size of entries", and AWS' collapse was due to an automation software bug.
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
In other words, even if every instance of React has been patched within nanoseconds of the vulnerability announcement, there are still plenty more ways for server admins to have yet another very bad day.

1. Best gaming chair: Secretlab Titan Evo
2. Best gaming desk: Secretlab Magnus Pro XL
3. Best gaming headset: Razer BlackShark V3
4. Best gaming keyboard: Asus ROG Strix Scope II 96 Wireless
5. Best gaming mouse: Razer DeathAdder V4 Pro
6. Best PC controller: GameSir G7 Pro
7. Best steering wheel: Logitech G Pro Racing Wheel
8. Best microphone: Shure MV6 USB Gaming Microphone
9. Best webcam: Elgato Facecam MK.2

Nick, gaming, and computers all first met in the early 1980s. After leaving university, he became a physics and IT teacher and started writing about tech in the late 1990s. That resulted in him working with MadOnion to write the help files for 3DMark and PCMark. After a short stint working at Beyond3D.com, Nick joined Futuremark (MadOnion rebranded) full-time, as editor-in-chief for its PC gaming section, YouGamers. After the site shutdown, he became an engineering and computing lecturer for many years, but missed the writing bug. Cue four years at TechSpot.com covering everything and anything to do with tech and PCs. He freely admits to being far too obsessed with GPUs and open-world grindy RPGs, but who isn't these days?
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.

