# More React CVEs Found! - Threat Wire

Source: https://www.youtube.com/watch?v=bhAVSXqxJ80
Recap page: https://rapidrecap.app/video/bhAVSXqxJ80
Generated: 2025-12-18T15:35:40.245+00:00

---
## Quick Overview

The video reports that three new high-severity and medium-severity CVEs were discovered in React Server Components, potentially allowing for Denial of Service or Source Code Exposure, and that Apple released emergency updates to patch two zero-day CVEs affecting WebKit, while Australia confirmed GitHub is not subject to its age-restricted social media ban, and Denmark proposed banning VPNs to curb internet piracy.

**Key Points:**
- Three new vulnerabilities (CVE-2025-55184, CVE-2025-67779, and CVE-2025-55183) were disclosed in React Server Components, including a high-severity Denial of Service (CVSS 7.5) and a medium-severity Source Code Exposure (CVSS 5.3).
- The high-severity DoS vulnerability involves a malicious HTTP request causing an infinite loop, while the Source Code Exposure vulnerability can return source code if an attacker sends a malicious request to a vulnerable Server Function endpoint.
- Apple released emergency updates to patch two zero-day CVEs (CVE-2025-4439 and CVE-2025-41474) affecting WebKit, which were actively being exploited in the wild.
- Australia's eSafety Commissioner confirmed that GitHub will not be subject to the new age-restricted social media ban, which goes into effect on December 10, 2025.
- The notorious hacking forum BreachForums reappeared via an email sent from an official French Ministry of the Interior domain, though some suspect it might be a honeypot or a failed law enforcement operation.
- Denmark proposed new legislation to ban the use of VPNs to prevent internet piracy, which critics warn could chill internet freedom.
- The host recommends checking out a video from the 'Not General Knowledge' YouTube channel regarding streaming piracy and the history of piracy.

![Screenshot at 00:09: The video transitions to an aerial map view of Washington D.C. while introducing the first topic about the potential death of the uncensored internet, setting a geopolitical context for regulatory news.](https://ss.rapidrecap.app/screens/bhAVSXqxJ80/00-00-09.png)

**Context:** This episode of Threat Wire, hosted by Allie Diamond, covers several recent developments in cybersecurity and internet regulation. The segment addresses newly disclosed vulnerabilities in the popular React framework, ongoing efforts by governments to regulate online content access (like Denmark's VPN ban proposal), and regulatory clarity regarding social media age restrictions in Australia. The host also discusses the suspicious reappearance of the dark web forum BreachForums.

## Detailed Analysis

The broadcast opens by addressing the potential end of the free internet, mentioning Australia's decision that GitHub will not be subject to its upcoming age-restricted social media ban, which requires platforms to prevent Australians under 16 from having accounts starting December 10, 2025. The host notes that while many major platforms like Facebook and TikTok are on the list, GitHub surprisingly was excluded. The discussion then shifts to the potential return of BreachForums, evidenced by an email sent from an official French Ministry of the Interior domain to previous members, leading to speculation about whether the site was seized by law enforcement or if the return is a honeypot trap. Following this, the focus moves to Denmark's proposal to ban VPNs, citing a survey that 9% of the population uses them to access foreign streaming media, with the proposed legislation aiming to undercut piracy protections granted under the 1996 Communications Decency Act, which shields platforms from liability for user content. Next, the segment details three new vulnerabilities found in React Server Components: two high-severity Denial of Service flaws (CVE-2025-55184 and CVE-2025-67779, both CVSS 7.5) that can cause an infinite loop and consume CPU, and one medium-severity Source Code Exposure flaw (CVE-2025-55183, CVSS 5.3). These issues affect all React Server Function endpoints, and users are urged to update immediately, noting that previous patches for one of the DoS issues were incomplete. Finally, the host mentions Apple releasing emergency updates for two zero-day vulnerabilities in WebKit that were actively being exploited. The episode concludes with a holiday greeting and a plug for the show's Patreon.

### Australian Social Media Age Restriction

- GitHub confirmed not to be age-restricted under the SMMA obligation set for December 10, 2025
- Facebook, Instagram, TikTok, and others are considered age-restricted
- Requires companies to prevent Australians under 16 from having accounts

### BreachForums Status

- Reappearance suggested by an email sent from the French Ministry of the Interior domain (interieur.gouv.fr)
- Raises suspicion of a honeypot or law enforcement operation
- Users visiting the site faced errors, suggesting technical issues or a trap

### Danish VPN Ban Proposal

- Denmark seeks to ban VPNs to prevent internet piracy, citing 9% of the population uses them for foreign content access
- Proposal aims to undermine protections under Section 230 of the Communications Decency Act
- Critics warn of a chilling effect on internet freedom

### React CVEs Disclosed

- Three new vulnerabilities found in React Server Components
- Two high-severity DoS flaws (CVSS 7.5) causing infinite loops, and one medium-severity Source Code Exposure flaw (CVSS 5.3)
- Patches are available, but previous fixes for one DoS were incomplete, requiring users to update again

### Apple WebKit Updates

- Apple released emergency updates to patch two zero-day CVEs actively exploited in the wild
- Flaws affected WebKit components

### Trending News Wrap-up

- OpenAI released a blog post detailing new models for cybersecurity decision-making
- Google Thread Analysis Group found threat actors exploiting unpatched React servers for malware, credential theft, and cryptomining

![Screenshot at 00:00: Host Allie Diamond introduces the weekly cybersecurity news roundup.](https://ss.rapidrecap.app/screens/bhAVSXqxJ80/00-00-00.png)
![Screenshot at 00:09: An aerial map background appears as the host discusses the potential end of the 'uncensored internet' and regulatory actions.](https://ss.rapidrecap.app/screens/bhAVSXqxJ80/00-00-09.png)
![Screenshot at 00:14: On-screen text confirms the first news item: "GitHub Not Banned In Australia".](https://ss.rapidrecap.app/screens/bhAVSXqxJ80/00-00-14.png)
![Screenshot at 01:30: On-screen text poses the question: "Is BreachForums Back?"](https://ss.rapidrecap.app/screens/bhAVSXqxJ80/00-01-30.png)
![Screenshot at 02:30: On-screen text poses the second news topic: "Is the Free Internet Forever?"](https://ss.rapidrecap.app/screens/bhAVSXqxJ80/00-02-30.png)
