Critical Security Vulnerability Disclosed in React Server Components
By BIOS Founding Team

The React team disclosed CVE-2025-55182, a critical (CVSS 10.0) unauthenticated remote code execution vulnerability affecting react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack across React 19.0 through 19.2.0, caused by a payload-deserialization flaw at React Server Function endpoints.
Developers were urged to upgrade immediately to patched versions, and downstream frameworks like Next.js and React Router shipped corresponding patches.
Full details: https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components
More from the community

Stable and Longterm Kernel Updates: 7.2.4, 6.18.50, 6.12.109
Greg Kroah-Hartman pushed out new stable and longterm point releases across the 7.2, 6.18, and 6.12 lines, each bundling accumulated fixes across drivers, filesystems, and core subsystems.

Rust Debugging Survey 2026 Results
The Rust Project published results from its 2026 debugging survey, gathering community feedback on debugging tools and workflows to guide future tooling investment.

Docker Desktop 4.90.0
This release made 'Ask Gordon,' Docker's AI assistant, accessible as a persistent right-side drawer and added one-click AI diagnosis for containers, images, and volumes with detected issues.