Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
React

React Vendor Cyber Rating & Cyber Score

reactjs.org

React is a JavaScript library for building user interfaces. It is maintained by Facebook and a community of individual developers and companies. React can be used as a base in the development of single-page or mobile applications.


React A.I CyberSecurity Scoring

React
Company Information
Website:https://reactjs.org/
Employees number:259
Number of followers:68,779
NAICS:5112
Industry Type:Software Development
Homepage:reactjs.org
React Risk Score (AI oriented)
Between 700 and 749
logo
ReactSoftware Development
Updated:
10/04/2026
744/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
React Global Score (TPRM)
xxxx
logo
ReactSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

React
ReactModerate
Current Score
744Ba (MODERATE)
01000
3 incidents
-4.33 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
745Before Incident
JUNE 2026
745Before Incident
MAY 2026
744Before Incident
APRIL 2026
749Before Incident
Vulnerability
10 Apr 2026React
React: React Server Components Vulnerability Enables DoS Attacks

High-Severity DoS Vulnerability in React Server Components Exposes Web Apps to Attacks

744After Incident
LOW-5
REA1775809531
High-Severity DoS Vulnerability in React Server Components Exposes Web Apps to Attacks A critical vulnerability (CVE-2026-23869) has been identified in React Server Components, enabling unauthenticated remote attackers to launch Denial of Service (DoS) attacks by exhausting backend server resources. The flaw, rated High severity by GitHub’s Security Advisory, requires no user interaction or elevated privileges, making it a significant risk for production environments using affected packages. The attack exploits weaknesses in how React Server Components process data at Server Function endpoints. Malicious HTTP requests trigger two vulnerabilities: - Deserialization of untrusted data (CWE-502), allowing unsafe input processing. - Uncontrolled resource consumption (CWE-400), forcing excessive CPU usage for up to a minute, degrading performance and blocking legitimate users. The vulnerability affects React 19.0, 19.1, and 19.2 branches, specifically these npm packages: - `react-server-dom-parcel` (versions 19.0.0–19.0.4, 19.1.0–19.1.5, 19.2.0–19.2.4) - `react-server-dom-turbopack` (same versions) - `react-server-dom-webpack` (same versions) Not all React apps are vulnerable only those using server-side rendering with affected packages. Client-side-only React applications or those without Server Component support remain unaffected. The React team has released patches in versions 19.0.5, 19.1.6, and 19.2.5, urging developers to upgrade immediately to mitigate the flaw.
INCIDENT DETAILS -
TYPE
Denial of Service (DoS)
IMPACT
Systems Affected: Backend servers using affected React Server Components packagesOperational Impact: Degraded performance, blocking legitimate users
MARCH 2026
749Before Incident
FEBRUARY 2026
753Before Incident
Vulnerability
06 Feb 2026React
React Native Community and Federal Civilian Executive Branch: CISA Warns of Actively Exploited React Native Community Command Injection Vulnerability

CISA Warns of Actively Exploited React Native CLI Vulnerability (CVE-2025-11953)

748After Incident
CRITICAL-5
REAFED1770374316
CISA Warns of Actively Exploited React Native CLI Vulnerability (CVE-2025-11953) The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-11953, a critical OS command injection vulnerability in the React Native Community Command-Line Interface (CLI), to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in the wild. The flaw affects the Metro Development Server, a core component of the React Native CLI used for bundling JavaScript during app development. Attackers can exploit the vulnerability by sending crafted POST requests to exposed Metro Server endpoints, enabling arbitrary command execution particularly severe on Windows systems, where it allows full control over development machines or build servers. Due to relaxed security controls in development environments, exposed Metro Servers (e.g., on public Wi-Fi or insecure networks) are prime targets for remote code execution (RCE), making this an attractive entry point for threat actors, including initial access brokers and data exfiltration campaigns. CISA has set a remediation deadline of February 26, 2026, for Federal Civilian Executive Branch (FCEB) agencies, mandating patches or discontinuation of vulnerable versions. The agency advises all organizations to: - Upgrade to the latest patched version of `@react-native-community/cli`. - Restrict access to Metro Servers, avoiding exposure to untrusted networks. - Monitor network logs for suspicious activity on the default Metro port (8081). Exploitation requires no authentication, and successful attacks could lead to privilege escalation or lateral movement within compromised environments. While the vulnerability primarily impacts development systems, its potential for full host compromise underscores the urgency of mitigation.
INCIDENT DETAILS -
TYPE
OS Command Injection
IMPACT
Systems Affected: Development machines, build serversOperational Impact: Full host compromise, privilege escalation, lateral movement
DATA BREACH
Data Exfiltration: Potential data exfiltration
JANUARY 2026
753Before Incident
DECEMBER 2025
755Before Incident
Vulnerability
05 Dec 2025React
Experts warn this 'worst case scenario' React vulnerability could soon be exploited - so patch now

Critical React flaw (CVE-2025-55182) enables pre-auth RCE in React Server Components

752After Incident
CRITICAL-3
REA1764965031
Critical React flaw (CVE-2025-55182) enables pre-auth RCE in React Server Components Affects versions 19.0–19.2.0 and frameworks like Next, React Router, Vite; patches released in 19.0.1, 19.1.2, 19.2.1 Experts warn exploitation is imminent with near 100% success rate; urgent upgrades strongly advised React is one of the most popular JavaScript libraries, which powers much of today’s internet. Researchers recently discovered a maximum-severity vulnerability. This bug could allow even the low-skilled threat actors to execute malicious code (RCE) on vulnerable instances. Earlier this week, the React team published a new security advisory detailing a pre-authentication bug in multiple versions of multiple packs, affecting React Server Components. The versions that are affected include 19.0, 19.1.0, 19.1.1, and 19.2.0, of react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack. The bug is now tracked as CVE-2025-55182, and was given a severity score of 10/10 (critical). Exploitation imminent - no doubt about it Default configurations of multiple React frameworks and bundlers are also affected by this bug, it was said, including next, react-router, waku, @parcel/rsc, @vitejs/plugin-rsc, and rwsdk. Versions that have addressed the bug are 19.0.1, 19.1.2, and 19.2.1, and React urges all users to apply the fix as soon as possible. "We recommend upgrading immediately," the React team said. According to The Register, React powers almost two in five of
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Systems Affected: React Server Components, frameworks (Next, React Router, Vite, Waku, @parcel/rsc, @vitejs/plugin-rsc, rwsdk)Operational Impact: Potential unauthorized code execution on vulnerable systemsBrand Reputation Impact: Potential damage due to critical vulnerability in widely used library
NOVEMBER 2025
755Before Incident
OCTOBER 2025
755Before Incident
SEPTEMBER 2025
755Before Incident
AUGUST 2025
755Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for React ?
?
What was React's A.I Rankiteo Cyber Score in June 2026 ?
?
What was React's A.I Rankiteo Cyber Score in May 2026 ?
?
What was React's A.I Rankiteo Cyber Score in April 2026 ?
?
What was React's A.I Rankiteo Cyber Score in March 2026 ?
?
What was React's A.I Rankiteo Cyber Score in February 2026 ?
?
What was React's A.I Rankiteo Cyber Score in January 2026 ?
?
What was React's A.I Rankiteo Cyber Score in December 2025 ?
?
What was React's A.I Rankiteo Cyber Score in November 2025 ?
?
What was React's A.I Rankiteo Cyber Score in October 2025 ?
?
What was React's A.I Rankiteo Cyber Score in September 2025 ?
?
What was React's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on React's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with React ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view React's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?