Skip to content

[Flight] Add more DoS mitigations to Flight Reply, and harden Flight#35632

Merged
unstubbable merged 2 commits intofacebook:mainfrom
unstubbable:flight-dos-mitigations
Jan 26, 2026
Merged

[Flight] Add more DoS mitigations to Flight Reply, and harden Flight#35632
unstubbable merged 2 commits intofacebook:mainfrom
unstubbable:flight-dos-mitigations

Conversation

@unstubbable
Copy link
Collaborator

This fixes security vulnerabilities in Server Functions.

This fixes security vulnerabilities in Server Functions.

Co-authored-by: Josh Story <[email protected]>
Co-authored-by: Janka Uryga <[email protected]>
Co-authored-by: Hendrik Liebau <[email protected]>
@unstubbable unstubbable requested a review from eps1lon January 26, 2026 19:09
@meta-cla meta-cla bot added the CLA Signed label Jan 26, 2026
@github-actions github-actions bot added the React Core Team Opened by a member of the React Core Team label Jan 26, 2026
@react-sizebot
Copy link

react-sizebot commented Jan 26, 2026

The size diff is too large to display in a single comment. The GitHub action for this pull request contains an artifact called 'sizebot-message.md' with the full message.

Generated by 🚫 dangerJS against d5324f4

@unstubbable unstubbable merged commit 1068027 into facebook:main Jan 26, 2026
233 of 234 checks passed
@unstubbable unstubbable deleted the flight-dos-mitigations branch January 26, 2026 19:25
github-actions bot pushed a commit that referenced this pull request Jan 26, 2026
…35632)

This fixes security vulnerabilities in Server Functions.

---------

Co-authored-by: Sebastian Markbåge <[email protected]>
Co-authored-by: Josh Story <[email protected]>
Co-authored-by: Janka Uryga <[email protected]>
Co-authored-by: Sebastian Sebbie Silbermann <[email protected]>

DiffTrain build for [1068027](1068027)
WhenMoon-afk added a commit to WhenMoon-afk/substratia.io that referenced this pull request Jan 31, 2026
Minor version bump for react, react-dom, and react-test-renderer.
Includes security fixes: DoS mitigations for Server Actions and
hardened Server Components (facebook/react#35632).

Part of Dependabot PR #40 split strategy — safe minor bumps first.

Co-Authored-By: Claude Opus 4.5 <[email protected]>
WhenMoon-afk added a commit to WhenMoon-afk/substratia.io that referenced this pull request Jan 31, 2026
Minor version bump for react, react-dom, and react-test-renderer.
Includes security fixes: DoS mitigations for Server Actions and
hardened Server Components (facebook/react#35632).

Part of Dependabot PR #40 split strategy — safe minor bumps first.

Co-authored-by: WhenMoon-afk <[email protected]>
Co-authored-by: Claude Opus 4.5 <[email protected]>
This was referenced Feb 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA Signed React Core Team Opened by a member of the React Core Team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants

Comments