The context · December 2025

React disclosed a critical vulnerability in React Server Components in December 2025. The advisory has been updated since its original publication; current remediation details should be taken from the maintained source. [1]

Discovery is an operational task

When a critical advisory appears, the first question is which deployed applications are affected. A dependency file in a repository is only part of the answer. Teams also need to know what was built, where it runs and who can make and release the change.

Make ownership findable

Connect applications to maintained repositories, deployed versions and responsible people. Include smaller internal services that may not receive daily attention. An inventory that cannot identify a release owner will slow the response precisely when decisions need to be made quickly.

Close the loop after the patch

Verify that the intended version is running and that the application’s important behaviour still works. Record exceptions and follow-up work. This retrospective draws on a public advisory; it is not a claim that Sansa or a client was affected. Consult the current advisory for technical remediation rather than relying on historical version numbers.

Source & context

React · Security advisory, 3 December 2025

This retrospective was written for the archive in September 2026. The linked primary source documents the announcement or event; the practical interpretation and proposed approach are Sansa’s editorial perspective. Public examples do not imply a client relationship. Product capabilities and guidance may have changed since the period discussed.

Another perspective · December 2025

A patch-response rehearsal for the applications you own

Continue reading

Working through a similar question?

Talk it through with Sansa