Maximum-severity vulnerability threatens 6% of all websites
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Security defenders are girding themselves in response to the disclosure of a maximum-severity vulnerability disclosed Wednesday in React Server, an open source package that’s widely used by websites and in cloud environments. The vulnerability is easy to exploit and allows hackers to execute malicious code on servers that run it. React is embedded in web apps running on servers so that remote devices render JavaScript and content more quickly and with fewer resources. React is used by an estimated 6 percent of all websites and 39 percent of cloud environments. When end users reload a page, React…