Skip to content

Fix React Server Components CVE vulnerabilities#2607

Open
Dargon789 wants to merge 1 commit intocoinbase:mainfrom
Dargon789:vercel/react
Open

Fix React Server Components CVE vulnerabilities#2607
Dargon789 wants to merge 1 commit intocoinbase:mainfrom
Dargon789:vercel/react

Conversation

@Dargon789
Copy link

Updated dependencies to fix Next.js and React CVE vulnerabilities.

The fix-react2shell-next tool automatically updated the following packages to their secure versions:

  • next
  • react-server-dom-webpack
  • react-server-dom-parcel
  • react-server-dom-turbopack

All package.json files have been scanned and vulnerable versions have been patched to the correct fixed versions based on the official React advisory.

What changed? Why?

Notes to reviewers

How has it been tested?

Updated dependencies to fix Next.js and React CVE vulnerabilities.

The fix-react2shell-next tool automatically updated the following packages to their secure versions:
- next
- react-server-dom-webpack
- react-server-dom-parcel  
- react-server-dom-turbopack

All package.json files have been scanned and vulnerable versions have been patched to the correct fixed versions based on the official React advisory.

Co-authored-by: Vercel <vercel[bot]@users.noreply.github.com>
@cb-heimdall
Copy link

🟡 Heimdall Review Status

Requirement Status More Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot 0
1 if user is external 0
2 if repo is sensitive 0
From .codeflow.yml 1
Additional review requirements
Show calculation
Max 0
0
From CODEOWNERS 0
Global minimum 0
Max 1
1
1 if commit is unverified 1
Sum 2

@vercel
Copy link

vercel bot commented Feb 1, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
onchainkit-playground Ready Ready Preview, Comment Feb 1, 2026 6:20pm
onchainkit-routes Ready Ready Preview, Comment Feb 1, 2026 6:20pm

Request Review

@vercel
Copy link

vercel bot commented Feb 1, 2026

@vercel[bot] is attempting to deploy a commit to the Coinbase Team on Vercel.

A member of the Team first needs to authorize it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants