Skip to content

[Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob - #36055

Merged
eps1lon merged 2 commits into
react:mainfrom
eps1lon:sebbie/did
Mar 17, 2026
Merged

[Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob#36055
eps1lon merged 2 commits into
react:mainfrom
eps1lon:sebbie/did

Conversation

@eps1lon

Copy link
Copy Markdown
Collaborator

Additional security hardening to bail out early for malformed Server Action payloads.

The $B (Blob) case in parseModelString returned whatever FormData.get() returned without validating its type. Since FormData.get() returns either a string or a File/Blob, an attacker could store a large string in a FormData slot and reference it via $B, bypassing the bumpArrayCount size guard that applies to regular string values. However, this does not lead to a real attack vector because it doesn't produce amplification. For that, it would need to be combined with regular references in nested arrays, which are covered by the array counting mitigation.

As a defense-in-depth mitigation, this adds an instanceof Blob check that rejects non-Blob backing entries. Bumping the array count for Blob size is not necessary because real Blobs are opaque handles — they don't expand during common operations like JSON.stringify (which produces {}), .flat(), or .toString(). The data only materializes through explicit reads like .text() or .arrayBuffer(), and since all references to the same $B ID resolve to the same object, there is no memory duplication.

@github-actionsgithub-actionsBot added the React Core Team Opened by a member of the React Core Team label Mar 17, 2026
@react-sizebot

Copy link
Copy Markdown

Comparing: c80a075...a46c5af

Critical size changes

Includes critical production bundles, as well as any change greater than 2%:

Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-stable/react-dom/cjs/react-dom-client.production.js=612.78 kB612.78 kB=108.29 kB108.29 kB
oss-experimental/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-experimental/react-dom/cjs/react-dom-client.production.js=678.71 kB678.71 kB=119.25 kB119.25 kB
facebook-www/ReactDOM-prod.classic.js=697.76 kB697.76 kB=122.60 kB122.60 kB
facebook-www/ReactDOM-prod.modern.js=688.08 kB688.08 kB=120.98 kB120.98 kB

Significant size changes

Includes any change greater than 0.2%:

(No significant changes)

Generated by 🚫 dangerJS against a46c5af

@eps1lon
eps1lon marked this pull request as ready for review March 17, 2026 10:45
@eps1lon
eps1lon merged commit 12ba7d8 into react:mainMar 17, 2026
245 checks passed
@eps1lon
eps1lon deleted the sebbie/did branch March 17, 2026 10:50
@ericadalton124-stack

ericadalton124-stack commented Mar 17, 2026 via email

Copy link
Copy Markdown

SyMind pushed a commit to SyMind/react that referenced this pull request Aug 11, 2026
* [Flight] Restore standard React version placeholder
* [Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob (react#36055)
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
(cherry picked from commit 12ba7d8)
* [Flight] Avoid consuming cyclic models multiple times
Co-authored-by: "Sebastian \"Sebbie\" Silbermann" <sebastian.silbermann@vercel.com>
(cherry picked from commit 672b242)
* [FlightReply] Type hardening and performance improvements
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
(cherry picked from commit 795203e)
* [FlightReply] Don't drop FormData entries in `decodeReplyFromBusboy` (react#36468)
Fixes a regression from react#36425 where referenced `FormData` entries can
be dropped by `decodeReplyFromBusboy` when files are interleaved with
text fields in the payload.
`decodeReplyFromBusboy` queues text fields that arrive while a file is
being streamed and flushes them after the last file's `'end'`, working
around busboy emitting `'end'` deferred relative to subsequent `'field'`
events. With multiple files interleaved with text, this loses the
relative order of the affected text entries. The reorder was a
long-standing but invisible issue — entries came back in the wrong order
but were all present — until react#36425 tightened how referenced FormData
entries are collected from the backing store to rely on them being
contiguous. With that assumption violated, referenced FormDatas can now
come back with some entries dropped. The pattern is most easily surfaced
through `useActionState` actions that return the submitted `FormData` as
part of their state.
This replaces the tail-flush with a linked list of pending files. Text
fields that arrive while a file is in flight are queued on the tail
file's `queuedFields`; fields that arrive when the list is empty resolve
immediately. `flush()` walks from the head, resolving each completed
file followed by its queued fields, and stops at the first file that
hasn't ended yet. The backing FormData now matches the payload's order,
restoring the contiguity assumption (and fixing the long-standing
reorder as a side effect). The same change is applied to all five copies
in `react-server-dom-{webpack,turbopack,parcel,esm,unbundled}`. Two new
tests cover the multi-file interleave.
fixesvercel/next.js#93822
(cherry picked from commit b91823e)
* [FlightReply] Performance improvements when decoding (react#37087)
This fixes security vulnerabilities in Server Functions.
(cherry picked from commit 1dd4ecb)
* [Flight Reply] Align Rspack decoders with upstream changes
Mirror the selected Reply changes into the Rspack-owned browser, edge, and Node adapters after the dependency-closed upstream backports.
Forward caller-provided array size limits, preserve multipart field/file order, and settle failed async iterators without recursive error re-entry. Add public behavior coverage across every Rspack decoder, action-selection path, cyclic collection type, iterator settlement, and Busboy ordering direction.
This is a tactical source-parity change for the existing proposal branch; it does not make that branch current with React main.
---------
Co-authored-by: Sebastian "Sebbie" Silbermann <sebastian.silbermann@vercel.com>
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA SignedReact Core TeamOpened by a member of the React Core Team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@eps1lon@react-sizebot@ericadalton124-stack@unstubbable
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
[Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob by eps1lon · Pull Request #36055 · react/react · GitHub
Skip to content

[Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob - #36055

Merged
eps1lon merged 2 commits into
react:mainfrom
eps1lon:sebbie/did
Mar 17, 2026
Merged

[Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob#36055
eps1lon merged 2 commits into
react:mainfrom
eps1lon:sebbie/did

Conversation

@eps1lon

Copy link
Copy Markdown
Collaborator

Additional security hardening to bail out early for malformed Server Action payloads.

The $B (Blob) case in parseModelString returned whatever FormData.get() returned without validating its type. Since FormData.get() returns either a string or a File/Blob, an attacker could store a large string in a FormData slot and reference it via $B, bypassing the bumpArrayCount size guard that applies to regular string values. However, this does not lead to a real attack vector because it doesn't produce amplification. For that, it would need to be combined with regular references in nested arrays, which are covered by the array counting mitigation.

As a defense-in-depth mitigation, this adds an instanceof Blob check that rejects non-Blob backing entries. Bumping the array count for Blob size is not necessary because real Blobs are opaque handles — they don't expand during common operations like JSON.stringify (which produces {}), .flat(), or .toString(). The data only materializes through explicit reads like .text() or .arrayBuffer(), and since all references to the same $B ID resolve to the same object, there is no memory duplication.

@github-actionsgithub-actionsBot added the React Core Team Opened by a member of the React Core Team label Mar 17, 2026
@react-sizebot

Copy link
Copy Markdown

Comparing: c80a075...a46c5af

Critical size changes

Includes critical production bundles, as well as any change greater than 2%:

Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-stable/react-dom/cjs/react-dom-client.production.js=612.78 kB612.78 kB=108.29 kB108.29 kB
oss-experimental/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-experimental/react-dom/cjs/react-dom-client.production.js=678.71 kB678.71 kB=119.25 kB119.25 kB
facebook-www/ReactDOM-prod.classic.js=697.76 kB697.76 kB=122.60 kB122.60 kB
facebook-www/ReactDOM-prod.modern.js=688.08 kB688.08 kB=120.98 kB120.98 kB

Significant size changes

Includes any change greater than 0.2%:

(No significant changes)

Generated by 🚫 dangerJS against a46c5af

@eps1lon
eps1lon marked this pull request as ready for review March 17, 2026 10:45
@eps1lon
eps1lon merged commit 12ba7d8 into react:mainMar 17, 2026
245 checks passed
@eps1lon
eps1lon deleted the sebbie/did branch March 17, 2026 10:50
@ericadalton124-stack

ericadalton124-stack commented Mar 17, 2026 via email

Copy link
Copy Markdown

SyMind pushed a commit to SyMind/react that referenced this pull request Aug 11, 2026
* [Flight] Restore standard React version placeholder
* [Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob (react#36055)
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
(cherry picked from commit 12ba7d8)
* [Flight] Avoid consuming cyclic models multiple times
Co-authored-by: "Sebastian \"Sebbie\" Silbermann" <sebastian.silbermann@vercel.com>
(cherry picked from commit 672b242)
* [FlightReply] Type hardening and performance improvements
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
(cherry picked from commit 795203e)
* [FlightReply] Don't drop FormData entries in `decodeReplyFromBusboy` (react#36468)
Fixes a regression from react#36425 where referenced `FormData` entries can
be dropped by `decodeReplyFromBusboy` when files are interleaved with
text fields in the payload.
`decodeReplyFromBusboy` queues text fields that arrive while a file is
being streamed and flushes them after the last file's `'end'`, working
around busboy emitting `'end'` deferred relative to subsequent `'field'`
events. With multiple files interleaved with text, this loses the
relative order of the affected text entries. The reorder was a
long-standing but invisible issue — entries came back in the wrong order
but were all present — until react#36425 tightened how referenced FormData
entries are collected from the backing store to rely on them being
contiguous. With that assumption violated, referenced FormDatas can now
come back with some entries dropped. The pattern is most easily surfaced
through `useActionState` actions that return the submitted `FormData` as
part of their state.
This replaces the tail-flush with a linked list of pending files. Text
fields that arrive while a file is in flight are queued on the tail
file's `queuedFields`; fields that arrive when the list is empty resolve
immediately. `flush()` walks from the head, resolving each completed
file followed by its queued fields, and stops at the first file that
hasn't ended yet. The backing FormData now matches the payload's order,
restoring the contiguity assumption (and fixing the long-standing
reorder as a side effect). The same change is applied to all five copies
in `react-server-dom-{webpack,turbopack,parcel,esm,unbundled}`. Two new
tests cover the multi-file interleave.
fixesvercel/next.js#93822
(cherry picked from commit b91823e)
* [FlightReply] Performance improvements when decoding (react#37087)
This fixes security vulnerabilities in Server Functions.
(cherry picked from commit 1dd4ecb)
* [Flight Reply] Align Rspack decoders with upstream changes
Mirror the selected Reply changes into the Rspack-owned browser, edge, and Node adapters after the dependency-closed upstream backports.
Forward caller-provided array size limits, preserve multipart field/file order, and settle failed async iterators without recursive error re-entry. Add public behavior coverage across every Rspack decoder, action-selection path, cyclic collection type, iterator settlement, and Busboy ordering direction.
This is a tactical source-parity change for the existing proposal branch; it does not make that branch current with React main.
---------
Co-authored-by: Sebastian "Sebbie" Silbermann <sebastian.silbermann@vercel.com>
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA SignedReact Core TeamOpened by a member of the React Core Team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@eps1lon@react-sizebot@ericadalton124-stack@unstubbable
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' [Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob by eps1lon · Pull Request #36055 · react/react · GitHub
Skip to content

[Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob - #36055

Merged
eps1lon merged 2 commits into
react:mainfrom
eps1lon:sebbie/did
Mar 17, 2026
Merged

[Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob#36055
eps1lon merged 2 commits into
react:mainfrom
eps1lon:sebbie/did

Conversation

@eps1lon

Copy link
Copy Markdown
Collaborator

Additional security hardening to bail out early for malformed Server Action payloads.

The $B (Blob) case in parseModelString returned whatever FormData.get() returned without validating its type. Since FormData.get() returns either a string or a File/Blob, an attacker could store a large string in a FormData slot and reference it via $B, bypassing the bumpArrayCount size guard that applies to regular string values. However, this does not lead to a real attack vector because it doesn't produce amplification. For that, it would need to be combined with regular references in nested arrays, which are covered by the array counting mitigation.

As a defense-in-depth mitigation, this adds an instanceof Blob check that rejects non-Blob backing entries. Bumping the array count for Blob size is not necessary because real Blobs are opaque handles — they don't expand during common operations like JSON.stringify (which produces {}), .flat(), or .toString(). The data only materializes through explicit reads like .text() or .arrayBuffer(), and since all references to the same $B ID resolve to the same object, there is no memory duplication.

@github-actionsgithub-actionsBot added the React Core Team Opened by a member of the React Core Team label Mar 17, 2026
@react-sizebot

Copy link
Copy Markdown

Comparing: c80a075...a46c5af

Critical size changes

Includes critical production bundles, as well as any change greater than 2%:

Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-stable/react-dom/cjs/react-dom-client.production.js=612.78 kB612.78 kB=108.29 kB108.29 kB
oss-experimental/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-experimental/react-dom/cjs/react-dom-client.production.js=678.71 kB678.71 kB=119.25 kB119.25 kB
facebook-www/ReactDOM-prod.classic.js=697.76 kB697.76 kB=122.60 kB122.60 kB
facebook-www/ReactDOM-prod.modern.js=688.08 kB688.08 kB=120.98 kB120.98 kB

Significant size changes

Includes any change greater than 0.2%:

(No significant changes)

Generated by 🚫 dangerJS against a46c5af

@eps1lon
eps1lon marked this pull request as ready for review March 17, 2026 10:45
@eps1lon
eps1lon merged commit 12ba7d8 into react:mainMar 17, 2026
245 checks passed
@eps1lon
eps1lon deleted the sebbie/did branch March 17, 2026 10:50
@ericadalton124-stack

ericadalton124-stack commented Mar 17, 2026 via email

Copy link
Copy Markdown

SyMind pushed a commit to SyMind/react that referenced this pull request Aug 11, 2026
* [Flight] Restore standard React version placeholder
* [Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob (react#36055)
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
(cherry picked from commit 12ba7d8)
* [Flight] Avoid consuming cyclic models multiple times
Co-authored-by: "Sebastian \"Sebbie\" Silbermann" <sebastian.silbermann@vercel.com>
(cherry picked from commit 672b242)
* [FlightReply] Type hardening and performance improvements
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
(cherry picked from commit 795203e)
* [FlightReply] Don't drop FormData entries in `decodeReplyFromBusboy` (react#36468)
Fixes a regression from react#36425 where referenced `FormData` entries can
be dropped by `decodeReplyFromBusboy` when files are interleaved with
text fields in the payload.
`decodeReplyFromBusboy` queues text fields that arrive while a file is
being streamed and flushes them after the last file's `'end'`, working
around busboy emitting `'end'` deferred relative to subsequent `'field'`
events. With multiple files interleaved with text, this loses the
relative order of the affected text entries. The reorder was a
long-standing but invisible issue — entries came back in the wrong order
but were all present — until react#36425 tightened how referenced FormData
entries are collected from the backing store to rely on them being
contiguous. With that assumption violated, referenced FormDatas can now
come back with some entries dropped. The pattern is most easily surfaced
through `useActionState` actions that return the submitted `FormData` as
part of their state.
This replaces the tail-flush with a linked list of pending files. Text
fields that arrive while a file is in flight are queued on the tail
file's `queuedFields`; fields that arrive when the list is empty resolve
immediately. `flush()` walks from the head, resolving each completed
file followed by its queued fields, and stops at the first file that
hasn't ended yet. The backing FormData now matches the payload's order,
restoring the contiguity assumption (and fixing the long-standing
reorder as a side effect). The same change is applied to all five copies
in `react-server-dom-{webpack,turbopack,parcel,esm,unbundled}`. Two new
tests cover the multi-file interleave.
fixesvercel/next.js#93822
(cherry picked from commit b91823e)
* [FlightReply] Performance improvements when decoding (react#37087)
This fixes security vulnerabilities in Server Functions.
(cherry picked from commit 1dd4ecb)
* [Flight Reply] Align Rspack decoders with upstream changes
Mirror the selected Reply changes into the Rspack-owned browser, edge, and Node adapters after the dependency-closed upstream backports.
Forward caller-provided array size limits, preserve multipart field/file order, and settle failed async iterators without recursive error re-entry. Add public behavior coverage across every Rspack decoder, action-selection path, cyclic collection type, iterator settlement, and Busboy ordering direction.
This is a tactical source-parity change for the existing proposal branch; it does not make that branch current with React main.
---------
Co-authored-by: Sebastian "Sebbie" Silbermann <sebastian.silbermann@vercel.com>
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA SignedReact Core TeamOpened by a member of the React Core Team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@eps1lon@react-sizebot@ericadalton124-stack@unstubbable
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' [Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob by eps1lon · Pull Request #36055 · react/react · GitHub
Skip to content

[Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob - #36055

Merged
eps1lon merged 2 commits into
react:mainfrom
eps1lon:sebbie/did
Mar 17, 2026
Merged

[Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob#36055
eps1lon merged 2 commits into
react:mainfrom
eps1lon:sebbie/did

Conversation

@eps1lon

Copy link
Copy Markdown
Collaborator

Additional security hardening to bail out early for malformed Server Action payloads.

The $B (Blob) case in parseModelString returned whatever FormData.get() returned without validating its type. Since FormData.get() returns either a string or a File/Blob, an attacker could store a large string in a FormData slot and reference it via $B, bypassing the bumpArrayCount size guard that applies to regular string values. However, this does not lead to a real attack vector because it doesn't produce amplification. For that, it would need to be combined with regular references in nested arrays, which are covered by the array counting mitigation.

As a defense-in-depth mitigation, this adds an instanceof Blob check that rejects non-Blob backing entries. Bumping the array count for Blob size is not necessary because real Blobs are opaque handles — they don't expand during common operations like JSON.stringify (which produces {}), .flat(), or .toString(). The data only materializes through explicit reads like .text() or .arrayBuffer(), and since all references to the same $B ID resolve to the same object, there is no memory duplication.

@github-actionsgithub-actionsBot added the React Core Team Opened by a member of the React Core Team label Mar 17, 2026
@react-sizebot

Copy link
Copy Markdown

Comparing: c80a075...a46c5af

Critical size changes

Includes critical production bundles, as well as any change greater than 2%:

Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-stable/react-dom/cjs/react-dom-client.production.js=612.78 kB612.78 kB=108.29 kB108.29 kB
oss-experimental/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-experimental/react-dom/cjs/react-dom-client.production.js=678.71 kB678.71 kB=119.25 kB119.25 kB
facebook-www/ReactDOM-prod.classic.js=697.76 kB697.76 kB=122.60 kB122.60 kB
facebook-www/ReactDOM-prod.modern.js=688.08 kB688.08 kB=120.98 kB120.98 kB

Significant size changes

Includes any change greater than 0.2%:

(No significant changes)

Generated by 🚫 dangerJS against a46c5af

@eps1lon
eps1lon marked this pull request as ready for review March 17, 2026 10:45
@eps1lon
eps1lon merged commit 12ba7d8 into react:mainMar 17, 2026
245 checks passed
@eps1lon
eps1lon deleted the sebbie/did branch March 17, 2026 10:50
@ericadalton124-stack

ericadalton124-stack commented Mar 17, 2026 via email

Copy link
Copy Markdown

SyMind pushed a commit to SyMind/react that referenced this pull request Aug 11, 2026
* [Flight] Restore standard React version placeholder
* [Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob (react#36055)
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
(cherry picked from commit 12ba7d8)
* [Flight] Avoid consuming cyclic models multiple times
Co-authored-by: "Sebastian \"Sebbie\" Silbermann" <sebastian.silbermann@vercel.com>
(cherry picked from commit 672b242)
* [FlightReply] Type hardening and performance improvements
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
(cherry picked from commit 795203e)
* [FlightReply] Don't drop FormData entries in `decodeReplyFromBusboy` (react#36468)
Fixes a regression from react#36425 where referenced `FormData` entries can
be dropped by `decodeReplyFromBusboy` when files are interleaved with
text fields in the payload.
`decodeReplyFromBusboy` queues text fields that arrive while a file is
being streamed and flushes them after the last file's `'end'`, working
around busboy emitting `'end'` deferred relative to subsequent `'field'`
events. With multiple files interleaved with text, this loses the
relative order of the affected text entries. The reorder was a
long-standing but invisible issue — entries came back in the wrong order
but were all present — until react#36425 tightened how referenced FormData
entries are collected from the backing store to rely on them being
contiguous. With that assumption violated, referenced FormDatas can now
come back with some entries dropped. The pattern is most easily surfaced
through `useActionState` actions that return the submitted `FormData` as
part of their state.
This replaces the tail-flush with a linked list of pending files. Text
fields that arrive while a file is in flight are queued on the tail
file's `queuedFields`; fields that arrive when the list is empty resolve
immediately. `flush()` walks from the head, resolving each completed
file followed by its queued fields, and stops at the first file that
hasn't ended yet. The backing FormData now matches the payload's order,
restoring the contiguity assumption (and fixing the long-standing
reorder as a side effect). The same change is applied to all five copies
in `react-server-dom-{webpack,turbopack,parcel,esm,unbundled}`. Two new
tests cover the multi-file interleave.
fixesvercel/next.js#93822
(cherry picked from commit b91823e)
* [FlightReply] Performance improvements when decoding (react#37087)
This fixes security vulnerabilities in Server Functions.
(cherry picked from commit 1dd4ecb)
* [Flight Reply] Align Rspack decoders with upstream changes
Mirror the selected Reply changes into the Rspack-owned browser, edge, and Node adapters after the dependency-closed upstream backports.
Forward caller-provided array size limits, preserve multipart field/file order, and settle failed async iterators without recursive error re-entry. Add public behavior coverage across every Rspack decoder, action-selection path, cyclic collection type, iterator settlement, and Busboy ordering direction.
This is a tactical source-parity change for the existing proposal branch; it does not make that branch current with React main.
---------
Co-authored-by: Sebastian "Sebbie" Silbermann <sebastian.silbermann@vercel.com>
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA SignedReact Core TeamOpened by a member of the React Core Team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@eps1lon@react-sizebot@ericadalton124-stack@unstubbable
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' [Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob by eps1lon · Pull Request #36055 · react/react · GitHub
Skip to content

[Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob - #36055

Merged
eps1lon merged 2 commits into
react:mainfrom
eps1lon:sebbie/did
Mar 17, 2026
Merged

[Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob#36055
eps1lon merged 2 commits into
react:mainfrom
eps1lon:sebbie/did

Conversation

@eps1lon

Copy link
Copy Markdown
Collaborator

Additional security hardening to bail out early for malformed Server Action payloads.

The $B (Blob) case in parseModelString returned whatever FormData.get() returned without validating its type. Since FormData.get() returns either a string or a File/Blob, an attacker could store a large string in a FormData slot and reference it via $B, bypassing the bumpArrayCount size guard that applies to regular string values. However, this does not lead to a real attack vector because it doesn't produce amplification. For that, it would need to be combined with regular references in nested arrays, which are covered by the array counting mitigation.

As a defense-in-depth mitigation, this adds an instanceof Blob check that rejects non-Blob backing entries. Bumping the array count for Blob size is not necessary because real Blobs are opaque handles — they don't expand during common operations like JSON.stringify (which produces {}), .flat(), or .toString(). The data only materializes through explicit reads like .text() or .arrayBuffer(), and since all references to the same $B ID resolve to the same object, there is no memory duplication.

@github-actionsgithub-actionsBot added the React Core Team Opened by a member of the React Core Team label Mar 17, 2026
@react-sizebot

Copy link
Copy Markdown

Comparing: c80a075...a46c5af

Critical size changes

Includes critical production bundles, as well as any change greater than 2%:

Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-stable/react-dom/cjs/react-dom-client.production.js=612.78 kB612.78 kB=108.29 kB108.29 kB
oss-experimental/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-experimental/react-dom/cjs/react-dom-client.production.js=678.71 kB678.71 kB=119.25 kB119.25 kB
facebook-www/ReactDOM-prod.classic.js=697.76 kB697.76 kB=122.60 kB122.60 kB
facebook-www/ReactDOM-prod.modern.js=688.08 kB688.08 kB=120.98 kB120.98 kB

Significant size changes

Includes any change greater than 0.2%:

(No significant changes)

Generated by 🚫 dangerJS against a46c5af

@eps1lon
eps1lon marked this pull request as ready for review March 17, 2026 10:45
@eps1lon
eps1lon merged commit 12ba7d8 into react:mainMar 17, 2026
245 checks passed
@eps1lon
eps1lon deleted the sebbie/did branch March 17, 2026 10:50
@ericadalton124-stack

ericadalton124-stack commented Mar 17, 2026 via email

Copy link
Copy Markdown

SyMind pushed a commit to SyMind/react that referenced this pull request Aug 11, 2026
* [Flight] Restore standard React version placeholder
* [Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob (react#36055)
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
(cherry picked from commit 12ba7d8)
* [Flight] Avoid consuming cyclic models multiple times
Co-authored-by: "Sebastian \"Sebbie\" Silbermann" <sebastian.silbermann@vercel.com>
(cherry picked from commit 672b242)
* [FlightReply] Type hardening and performance improvements
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
(cherry picked from commit 795203e)
* [FlightReply] Don't drop FormData entries in `decodeReplyFromBusboy` (react#36468)
Fixes a regression from react#36425 where referenced `FormData` entries can
be dropped by `decodeReplyFromBusboy` when files are interleaved with
text fields in the payload.
`decodeReplyFromBusboy` queues text fields that arrive while a file is
being streamed and flushes them after the last file's `'end'`, working
around busboy emitting `'end'` deferred relative to subsequent `'field'`
events. With multiple files interleaved with text, this loses the
relative order of the affected text entries. The reorder was a
long-standing but invisible issue — entries came back in the wrong order
but were all present — until react#36425 tightened how referenced FormData
entries are collected from the backing store to rely on them being
contiguous. With that assumption violated, referenced FormDatas can now
come back with some entries dropped. The pattern is most easily surfaced
through `useActionState` actions that return the submitted `FormData` as
part of their state.
This replaces the tail-flush with a linked list of pending files. Text
fields that arrive while a file is in flight are queued on the tail
file's `queuedFields`; fields that arrive when the list is empty resolve
immediately. `flush()` walks from the head, resolving each completed
file followed by its queued fields, and stops at the first file that
hasn't ended yet. The backing FormData now matches the payload's order,
restoring the contiguity assumption (and fixing the long-standing
reorder as a side effect). The same change is applied to all five copies
in `react-server-dom-{webpack,turbopack,parcel,esm,unbundled}`. Two new
tests cover the multi-file interleave.
fixesvercel/next.js#93822
(cherry picked from commit b91823e)
* [FlightReply] Performance improvements when decoding (react#37087)
This fixes security vulnerabilities in Server Functions.
(cherry picked from commit 1dd4ecb)
* [Flight Reply] Align Rspack decoders with upstream changes
Mirror the selected Reply changes into the Rspack-owned browser, edge, and Node adapters after the dependency-closed upstream backports.
Forward caller-provided array size limits, preserve multipart field/file order, and settle failed async iterators without recursive error re-entry. Add public behavior coverage across every Rspack decoder, action-selection path, cyclic collection type, iterator settlement, and Busboy ordering direction.
This is a tactical source-parity change for the existing proposal branch; it does not make that branch current with React main.
---------
Co-authored-by: Sebastian "Sebbie" Silbermann <sebastian.silbermann@vercel.com>
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA SignedReact Core TeamOpened by a member of the React Core Team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@eps1lon@react-sizebot@ericadalton124-stack@unstubbable
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' [Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob by eps1lon · Pull Request #36055 · react/react · GitHub
Skip to content

[Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob - #36055

Merged
eps1lon merged 2 commits into
react:mainfrom
eps1lon:sebbie/did
Mar 17, 2026
Merged

[Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob#36055
eps1lon merged 2 commits into
react:mainfrom
eps1lon:sebbie/did

Conversation

@eps1lon

Copy link
Copy Markdown
Collaborator

Additional security hardening to bail out early for malformed Server Action payloads.

The $B (Blob) case in parseModelString returned whatever FormData.get() returned without validating its type. Since FormData.get() returns either a string or a File/Blob, an attacker could store a large string in a FormData slot and reference it via $B, bypassing the bumpArrayCount size guard that applies to regular string values. However, this does not lead to a real attack vector because it doesn't produce amplification. For that, it would need to be combined with regular references in nested arrays, which are covered by the array counting mitigation.

As a defense-in-depth mitigation, this adds an instanceof Blob check that rejects non-Blob backing entries. Bumping the array count for Blob size is not necessary because real Blobs are opaque handles — they don't expand during common operations like JSON.stringify (which produces {}), .flat(), or .toString(). The data only materializes through explicit reads like .text() or .arrayBuffer(), and since all references to the same $B ID resolve to the same object, there is no memory duplication.

@github-actionsgithub-actionsBot added the React Core Team Opened by a member of the React Core Team label Mar 17, 2026
@react-sizebot

Copy link
Copy Markdown

Comparing: c80a075...a46c5af

Critical size changes

Includes critical production bundles, as well as any change greater than 2%:

Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-stable/react-dom/cjs/react-dom-client.production.js=612.78 kB612.78 kB=108.29 kB108.29 kB
oss-experimental/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-experimental/react-dom/cjs/react-dom-client.production.js=678.71 kB678.71 kB=119.25 kB119.25 kB
facebook-www/ReactDOM-prod.classic.js=697.76 kB697.76 kB=122.60 kB122.60 kB
facebook-www/ReactDOM-prod.modern.js=688.08 kB688.08 kB=120.98 kB120.98 kB

Significant size changes

Includes any change greater than 0.2%:

(No significant changes)

Generated by 🚫 dangerJS against a46c5af

@eps1lon
eps1lon marked this pull request as ready for review March 17, 2026 10:45
@eps1lon
eps1lon merged commit 12ba7d8 into react:mainMar 17, 2026
245 checks passed
@eps1lon
eps1lon deleted the sebbie/did branch March 17, 2026 10:50
@ericadalton124-stack

ericadalton124-stack commented Mar 17, 2026 via email

Copy link
Copy Markdown

SyMind pushed a commit to SyMind/react that referenced this pull request Aug 11, 2026
* [Flight] Restore standard React version placeholder
* [Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob (react#36055)
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
(cherry picked from commit 12ba7d8)
* [Flight] Avoid consuming cyclic models multiple times
Co-authored-by: "Sebastian \"Sebbie\" Silbermann" <sebastian.silbermann@vercel.com>
(cherry picked from commit 672b242)
* [FlightReply] Type hardening and performance improvements
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
(cherry picked from commit 795203e)
* [FlightReply] Don't drop FormData entries in `decodeReplyFromBusboy` (react#36468)
Fixes a regression from react#36425 where referenced `FormData` entries can
be dropped by `decodeReplyFromBusboy` when files are interleaved with
text fields in the payload.
`decodeReplyFromBusboy` queues text fields that arrive while a file is
being streamed and flushes them after the last file's `'end'`, working
around busboy emitting `'end'` deferred relative to subsequent `'field'`
events. With multiple files interleaved with text, this loses the
relative order of the affected text entries. The reorder was a
long-standing but invisible issue — entries came back in the wrong order
but were all present — until react#36425 tightened how referenced FormData
entries are collected from the backing store to rely on them being
contiguous. With that assumption violated, referenced FormDatas can now
come back with some entries dropped. The pattern is most easily surfaced
through `useActionState` actions that return the submitted `FormData` as
part of their state.
This replaces the tail-flush with a linked list of pending files. Text
fields that arrive while a file is in flight are queued on the tail
file's `queuedFields`; fields that arrive when the list is empty resolve
immediately. `flush()` walks from the head, resolving each completed
file followed by its queued fields, and stops at the first file that
hasn't ended yet. The backing FormData now matches the payload's order,
restoring the contiguity assumption (and fixing the long-standing
reorder as a side effect). The same change is applied to all five copies
in `react-server-dom-{webpack,turbopack,parcel,esm,unbundled}`. Two new
tests cover the multi-file interleave.
fixesvercel/next.js#93822
(cherry picked from commit b91823e)
* [FlightReply] Performance improvements when decoding (react#37087)
This fixes security vulnerabilities in Server Functions.
(cherry picked from commit 1dd4ecb)
* [Flight Reply] Align Rspack decoders with upstream changes
Mirror the selected Reply changes into the Rspack-owned browser, edge, and Node adapters after the dependency-closed upstream backports.
Forward caller-provided array size limits, preserve multipart field/file order, and settle failed async iterators without recursive error re-entry. Add public behavior coverage across every Rspack decoder, action-selection path, cyclic collection type, iterator settlement, and Busboy ordering direction.
This is a tactical source-parity change for the existing proposal branch; it does not make that branch current with React main.
---------
Co-authored-by: Sebastian "Sebbie" Silbermann <sebastian.silbermann@vercel.com>
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA SignedReact Core TeamOpened by a member of the React Core Team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@eps1lon@react-sizebot@ericadalton124-stack@unstubbable
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' [Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob by eps1lon · Pull Request #36055 · react/react · GitHub
Skip to content

[Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob - #36055

Merged
eps1lon merged 2 commits into
react:mainfrom
eps1lon:sebbie/did
Mar 17, 2026
Merged

[Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob#36055
eps1lon merged 2 commits into
react:mainfrom
eps1lon:sebbie/did

Conversation

@eps1lon

Copy link
Copy Markdown
Collaborator

Additional security hardening to bail out early for malformed Server Action payloads.

The $B (Blob) case in parseModelString returned whatever FormData.get() returned without validating its type. Since FormData.get() returns either a string or a File/Blob, an attacker could store a large string in a FormData slot and reference it via $B, bypassing the bumpArrayCount size guard that applies to regular string values. However, this does not lead to a real attack vector because it doesn't produce amplification. For that, it would need to be combined with regular references in nested arrays, which are covered by the array counting mitigation.

As a defense-in-depth mitigation, this adds an instanceof Blob check that rejects non-Blob backing entries. Bumping the array count for Blob size is not necessary because real Blobs are opaque handles — they don't expand during common operations like JSON.stringify (which produces {}), .flat(), or .toString(). The data only materializes through explicit reads like .text() or .arrayBuffer(), and since all references to the same $B ID resolve to the same object, there is no memory duplication.

@github-actionsgithub-actionsBot added the React Core Team Opened by a member of the React Core Team label Mar 17, 2026
@react-sizebot

Copy link
Copy Markdown

Comparing: c80a075...a46c5af

Critical size changes

Includes critical production bundles, as well as any change greater than 2%:

Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-stable/react-dom/cjs/react-dom-client.production.js=612.78 kB612.78 kB=108.29 kB108.29 kB
oss-experimental/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-experimental/react-dom/cjs/react-dom-client.production.js=678.71 kB678.71 kB=119.25 kB119.25 kB
facebook-www/ReactDOM-prod.classic.js=697.76 kB697.76 kB=122.60 kB122.60 kB
facebook-www/ReactDOM-prod.modern.js=688.08 kB688.08 kB=120.98 kB120.98 kB

Significant size changes

Includes any change greater than 0.2%:

(No significant changes)

Generated by 🚫 dangerJS against a46c5af

@eps1lon
eps1lon marked this pull request as ready for review March 17, 2026 10:45
@eps1lon
eps1lon merged commit 12ba7d8 into react:mainMar 17, 2026
245 checks passed
@eps1lon
eps1lon deleted the sebbie/did branch March 17, 2026 10:50
@ericadalton124-stack

ericadalton124-stack commented Mar 17, 2026 via email

Copy link
Copy Markdown

SyMind pushed a commit to SyMind/react that referenced this pull request Aug 11, 2026
* [Flight] Restore standard React version placeholder
* [Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob (react#36055)
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
(cherry picked from commit 12ba7d8)
* [Flight] Avoid consuming cyclic models multiple times
Co-authored-by: "Sebastian \"Sebbie\" Silbermann" <sebastian.silbermann@vercel.com>
(cherry picked from commit 672b242)
* [FlightReply] Type hardening and performance improvements
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
(cherry picked from commit 795203e)
* [FlightReply] Don't drop FormData entries in `decodeReplyFromBusboy` (react#36468)
Fixes a regression from react#36425 where referenced `FormData` entries can
be dropped by `decodeReplyFromBusboy` when files are interleaved with
text fields in the payload.
`decodeReplyFromBusboy` queues text fields that arrive while a file is
being streamed and flushes them after the last file's `'end'`, working
around busboy emitting `'end'` deferred relative to subsequent `'field'`
events. With multiple files interleaved with text, this loses the
relative order of the affected text entries. The reorder was a
long-standing but invisible issue — entries came back in the wrong order
but were all present — until react#36425 tightened how referenced FormData
entries are collected from the backing store to rely on them being
contiguous. With that assumption violated, referenced FormDatas can now
come back with some entries dropped. The pattern is most easily surfaced
through `useActionState` actions that return the submitted `FormData` as
part of their state.
This replaces the tail-flush with a linked list of pending files. Text
fields that arrive while a file is in flight are queued on the tail
file's `queuedFields`; fields that arrive when the list is empty resolve
immediately. `flush()` walks from the head, resolving each completed
file followed by its queued fields, and stops at the first file that
hasn't ended yet. The backing FormData now matches the payload's order,
restoring the contiguity assumption (and fixing the long-standing
reorder as a side effect). The same change is applied to all five copies
in `react-server-dom-{webpack,turbopack,parcel,esm,unbundled}`. Two new
tests cover the multi-file interleave.
fixesvercel/next.js#93822
(cherry picked from commit b91823e)
* [FlightReply] Performance improvements when decoding (react#37087)
This fixes security vulnerabilities in Server Functions.
(cherry picked from commit 1dd4ecb)
* [Flight Reply] Align Rspack decoders with upstream changes
Mirror the selected Reply changes into the Rspack-owned browser, edge, and Node adapters after the dependency-closed upstream backports.
Forward caller-provided array size limits, preserve multipart field/file order, and settle failed async iterators without recursive error re-entry. Add public behavior coverage across every Rspack decoder, action-selection path, cyclic collection type, iterator settlement, and Busboy ordering direction.
This is a tactical source-parity change for the existing proposal branch; it does not make that branch current with React main.
---------
Co-authored-by: Sebastian "Sebbie" Silbermann <sebastian.silbermann@vercel.com>
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA SignedReact Core TeamOpened by a member of the React Core Team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@eps1lon@react-sizebot@ericadalton124-stack@unstubbable
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); [Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob by eps1lon · Pull Request #36055 · react/react · GitHub
Skip to content

[Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob - #36055

Merged
eps1lon merged 2 commits into
react:mainfrom
eps1lon:sebbie/did
Mar 17, 2026
Merged

[Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob#36055
eps1lon merged 2 commits into
react:mainfrom
eps1lon:sebbie/did

Conversation

@eps1lon

Copy link
Copy Markdown
Collaborator

Additional security hardening to bail out early for malformed Server Action payloads.

The $B (Blob) case in parseModelString returned whatever FormData.get() returned without validating its type. Since FormData.get() returns either a string or a File/Blob, an attacker could store a large string in a FormData slot and reference it via $B, bypassing the bumpArrayCount size guard that applies to regular string values. However, this does not lead to a real attack vector because it doesn't produce amplification. For that, it would need to be combined with regular references in nested arrays, which are covered by the array counting mitigation.

As a defense-in-depth mitigation, this adds an instanceof Blob check that rejects non-Blob backing entries. Bumping the array count for Blob size is not necessary because real Blobs are opaque handles — they don't expand during common operations like JSON.stringify (which produces {}), .flat(), or .toString(). The data only materializes through explicit reads like .text() or .arrayBuffer(), and since all references to the same $B ID resolve to the same object, there is no memory duplication.

@github-actionsgithub-actionsBot added the React Core Team Opened by a member of the React Core Team label Mar 17, 2026
@react-sizebot

Copy link
Copy Markdown

Comparing: c80a075...a46c5af

Critical size changes

Includes critical production bundles, as well as any change greater than 2%:

Name+/-BaseCurrent+/- gzipBase gzipCurrent gzip
oss-stable/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-stable/react-dom/cjs/react-dom-client.production.js=612.78 kB612.78 kB=108.29 kB108.29 kB
oss-experimental/react-dom/cjs/react-dom.production.js=6.84 kB6.84 kB=1.88 kB1.88 kB
oss-experimental/react-dom/cjs/react-dom-client.production.js=678.71 kB678.71 kB=119.25 kB119.25 kB
facebook-www/ReactDOM-prod.classic.js=697.76 kB697.76 kB=122.60 kB122.60 kB
facebook-www/ReactDOM-prod.modern.js=688.08 kB688.08 kB=120.98 kB120.98 kB

Significant size changes

Includes any change greater than 0.2%:

(No significant changes)

Generated by 🚫 dangerJS against a46c5af

@eps1lon
eps1lon marked this pull request as ready for review March 17, 2026 10:45
@eps1lon
eps1lon merged commit 12ba7d8 into react:mainMar 17, 2026
245 checks passed
@eps1lon
eps1lon deleted the sebbie/did branch March 17, 2026 10:50
@ericadalton124-stack

ericadalton124-stack commented Mar 17, 2026 via email

Copy link
Copy Markdown

SyMind pushed a commit to SyMind/react that referenced this pull request Aug 11, 2026
* [Flight] Restore standard React version placeholder
* [Flight Reply] Early bailout if backing entry for Blob deserialization is not a Blob (react#36055)
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
(cherry picked from commit 12ba7d8)
* [Flight] Avoid consuming cyclic models multiple times
Co-authored-by: "Sebastian \"Sebbie\" Silbermann" <sebastian.silbermann@vercel.com>
(cherry picked from commit 672b242)
* [FlightReply] Type hardening and performance improvements
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
(cherry picked from commit 795203e)
* [FlightReply] Don't drop FormData entries in `decodeReplyFromBusboy` (react#36468)
Fixes a regression from react#36425 where referenced `FormData` entries can
be dropped by `decodeReplyFromBusboy` when files are interleaved with
text fields in the payload.
`decodeReplyFromBusboy` queues text fields that arrive while a file is
being streamed and flushes them after the last file's `'end'`, working
around busboy emitting `'end'` deferred relative to subsequent `'field'`
events. With multiple files interleaved with text, this loses the
relative order of the affected text entries. The reorder was a
long-standing but invisible issue — entries came back in the wrong order
but were all present — until react#36425 tightened how referenced FormData
entries are collected from the backing store to rely on them being
contiguous. With that assumption violated, referenced FormDatas can now
come back with some entries dropped. The pattern is most easily surfaced
through `useActionState` actions that return the submitted `FormData` as
part of their state.
This replaces the tail-flush with a linked list of pending files. Text
fields that arrive while a file is in flight are queued on the tail
file's `queuedFields`; fields that arrive when the list is empty resolve
immediately. `flush()` walks from the head, resolving each completed
file followed by its queued fields, and stops at the first file that
hasn't ended yet. The backing FormData now matches the payload's order,
restoring the contiguity assumption (and fixing the long-standing
reorder as a side effect). The same change is applied to all five copies
in `react-server-dom-{webpack,turbopack,parcel,esm,unbundled}`. Two new
tests cover the multi-file interleave.
fixesvercel/next.js#93822
(cherry picked from commit b91823e)
* [FlightReply] Performance improvements when decoding (react#37087)
This fixes security vulnerabilities in Server Functions.
(cherry picked from commit 1dd4ecb)
* [Flight Reply] Align Rspack decoders with upstream changes
Mirror the selected Reply changes into the Rspack-owned browser, edge, and Node adapters after the dependency-closed upstream backports.
Forward caller-provided array size limits, preserve multipart field/file order, and settle failed async iterators without recursive error re-entry. Add public behavior coverage across every Rspack decoder, action-selection path, cyclic collection type, iterator settlement, and Busboy ordering direction.
This is a tactical source-parity change for the existing proposal branch; it does not make that branch current with React main.
---------
Co-authored-by: Sebastian "Sebbie" Silbermann <sebastian.silbermann@vercel.com>
Co-authored-by: Hendrik Liebau <mail@hendrik-liebau.de>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA SignedReact Core TeamOpened by a member of the React Core Team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@eps1lon@react-sizebot@ericadalton124-stack@unstubbable