TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise Here
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Internet

Cloudflare Blames React2Shell Protections for Outage

Akinola Ajibola by Akinola Ajibola
December 6, 2025
in Internet
Share on FacebookShare on Twitter

Yes, Cloudflare has acknowledged that modifications made to its systems to address the serious “React2Shell” vulnerability directly caused a recent outage.

The global service outage that occurred on Friday, December 5, 2025, resulted in the failure of websites and online platforms all across the world, was caused by an internal error “500 Internal Server Error” notice, in the emergency patch rollout for a security vulnerability that affected the whole industry rather than a cyberattack. 

The event has now been attributed by the internet infrastructure business to the implementation of emergency mitigations intended to address a severe remote code execution vulnerability in React Server Components that is currently being aggressively exploited in attacks.

“Neither a cyberattack on Cloudflare’s systems nor any other malicious activity was directly or indirectly responsible for the problem. In a post-mortem, Cloudflare CTO Dane Knecht stated that it was instead caused by modifications made to our body parsing mechanism while trying to identify and address an industry-wide vulnerability found in React Server Components this week.

“A subset of customers were impacted, accounting for approximately 28% of all HTTP traffic served by Cloudflare.”

This high-severity security bug (named React2Shell) affects the React open-source JavaScript library for web and native user interfaces, as well as dependent React frameworks including Next.js, React Router, Waku, @parcel/rsc, @vitejs/plugin-rsc, and RedwoodSDK.

The vulnerability was discovered in the React Server Components (RSC) ‘Flight’ protocol, which allows unauthenticated attackers to gain remote code execution in React and Next.js applications by submitting malicious HTTP requests to React Server Function endpoints.

While numerous React packages in their default configuration (e.g., react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack) are susceptible, the problem only affects React versions 19.0, 19.1.0, 19.1.1, and 19.2.0 released within the last year.

The continuous exploitation of React2Shell according to security researchers with Amazon Web Services (AWS) have reported that several China-affiliated hacking groups, such as Earth Lamia and Jackpot Panda, have started exploiting the React2Shell vulnerability hours after the max-severity flaw was revealed, though the impact is not as widespread as initially thought.

Additionally, the NHS England National CSOC stated on Thursday that there are currently a number of working proof-of-concept attacks for CVE-2025-55182 and cautioned that “continued successful exploitation in the wild is highly likely.”

Cloudflare’s Global Network was unavailable for over six hours last month due to another global outage, which CEO Matthew Prince called the “worst outage since 2019.” 

In June, Cloudflare resolved yet another significant outage that affected Google Cloud’s infrastructure and resulted in Access authentication failures and Zero Trust WARP connectivity problems in several locations.

CVE-2025-55182 (also known as “React2Shell”) is the vulnerability that triggered the emergency action. It is a critical remote code execution (RCE) bug (10.0 CVSS score) discovered in the React Server Components (RSC) ‘Flight’ protocol that may be abused without authentication via unsafe deserialisation.

The vulnerability was aggressively exploited in the wild by threat actors linked to China within hours of its public announcement on December 3, 2025, prompting immediate action by service providers including Cloudflare.

Related Posts:

  • Downdetector-OG
    Downdetector Breaks Down 2025’s Biggest Service Outages
  • 020224_cloudflare
    Cloudflare Blames Configuration Error for Major Outage
  • 5VIIZOZEEBK77IUN2Y3XCL4C54
    Cloud Outage At Amazon's North Virginia Data Centre Resolved
  • x office
    X Hit By Another Brief Outage
  • -1x-1 (14)
    Cloudflare Outage Disrupts X, ChatGPT, and Major Sites
  • 1520141277742
    YouTube & Google Hit By Ongoing Outages As Reports Spike
  • twitter-x-e1690183153269
    Outage Spurs On X as Users Report Service Disruptions
  • x-logo-phone-2025
    Real-Time Updates As X Experiences Worldwide Outage

Discover more from TechBooky

Subscribe to get the latest posts sent to your email.

Tags: cloudflarecloudflare down
Akinola Ajibola

Akinola Ajibola

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Elon Musk Hits $1.1 Trillion as SpaceX Surpasses $2 Trillion Valuation June 13, 2026
  • SpaceX Prices Record $75 Billion IPO as Elon Musk Nears Trillionaire Status June 12, 2026
  • DoorDash Launches AI Chatbot for Food Orders June 12, 2026
  • Pool Launches App That Makes Screenshots More Useful June 12, 2026
  • Deezer Launches Tool to Detect AI-Generated Music June 12, 2026
  • Coinbase Introduces Platform for Agents to Trade Assets and Buy Premium Insights June 12, 2026
  • Meta Expands Edits App With AI Features and Desktop Access June 12, 2026
  • Ready-made LMS and custom development. Pros and cons of each path. June 11, 2026
  • TELCOs Pay 75 Million Users For Poor Network Service June 10, 2026
  • Anthropic Launches Claude Fable 5, Bringing Mythos-Class AI to the Public June 10, 2026
  • Discord Data Breach Reportedly Impacts Over 10 Million Users June 10, 2026
  • TikTok Removed Four Million Videos & Disrupted 86,000 LIVE Sessions In Nigeria June 10, 2026

Browse Archives

June 2026
MTWTFSS
1234567
891011121314
15161718192021
22232425262728
2930 
« May    

Quick Links

  • About TechBooky
  • Advertise Here
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise Here
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.