
We Need To Talk About The React Hack... (Iâve Never Seen A Vulnerability This Bad.)
The Programming Podcast
Intro
Danny and Leon introduce a critical React/Next.js vulnerability and preview episode topics and sponsors.
đš Severity 10/10: The React Exploit That Shocked the Web Dev World
Imagine waking up to find your server blocked for mining crypto for a stranger.
Thatâs exactly what happened to developers this week, thanks to a critical vulnerability in React and Next.js that enabled full root-level server takeover.
In this episode of The Programming Podcast, we break down the âPerfect Hackâ step-by-step, how Vercel burned $750,000 in a single weekend to contain it, and the one line in your Dockerfile that might be leaving your environment exposed.
Then we shift gears into a tough career conversation:
Are you a âTourist Developerâ, constantly learning, never shipping?
If youâve got 50 tabs open and 0 deployed code⊠the second half of this episode is for you.
SITE https://www.programmingpodcast.com/
đĄ Sponsor: Level Up Financial Planning
Changing careers or increasing your income? Get financial clarity with Level Up Financial Planningâhelping early and mid-career tech professionals secure their financial future. Visit LevelUpFinancialPlanning.com for a free consultation!
https://www.levelupfinancialplanning.com/
Stay in Touch:
đ§ Have ideas or questions for the show? Or are you a business that wants to talk business?
Email us at dannyandleonspodcast@gmail.com!
Danny Thompson
https://x.com/DThompsonDev
https://www.linkedin.com/in/DThompsonDev
www.DThompsonDev.com
Leon Noel
https://x.com/leonnoel
https://www.linkedin.com/in/leonnoel/
https://100devs.org/
đ§ Have ideas or questions for the show? Or are you a business that wants to talk business?
Email us at dannyandleonspodcast@gmail.com!
What We Cover
- The âReact to Shellâ exploit (Non-technical AND technical explanations)
- Why running Docker as root is a catastrophic security mistake
- How Cloudflare accidentally broke part of the internet trying to patch this
- The Parking Lot Method to finally stop getting derailed by side quests
- How to identify if youâre stuck in Tourist Developer Mode
â±ïž CHAPTERS
0:00 â The Nightmare: Server hijacked for crypto mining
2:29 â CRITICAL WARNING: Update React Now
3:55 â Anatomy of the Attack (361% CPU Spikes)
6:50 â The Fatal Mistake: Docker as Root
12:43 â The âRestaurantâ Analogy (Explaining the Hack)
17:08 â Sponsored Segment
18:20 â Technical Deep Dive: Flight Protocol & Serialization
20:59 â The One Line of Code That Fixes It
23:44 â Vercelâs $750,000 Weekend Response
40:17 â How Cloudflare Accidentally Broke the Internet
42:33 â Career Q&A: âI keep getting distracted by side questsâ
48:36 â Are You a Tourist in Your Own Career?
51:08 â The Parking Lot Method for Focus
54:27 â The Index Card System for Goals
đ Resources
Guillermo Rauchâs Full Breakdown â https://x.com/rauchg/status/1997362942929440937
Eduardoâs Original Report â https://x.com/duborges/status/1997293892090183772
đ 45% of you arenât subscribed.
If you like content that makes our moms proud, hit that subscribe button.


