AWS Security ChangesHomeSearch

AWS waf high security documentation change

Service: waf · 2025-12-07 · Security-related high

File: waf/latest/developerguide/aws-managed-rule-groups-changelog.md

Summary

Documented update to ReactJSRCE_BODY rule for CVE-2025-55182 detection

Security assessment

The changelog entry explicitly references mitigation of CVE-2025-55182 (remote code execution vulnerability), indicating security-focused documentation updates.

Diff

diff --git a/waf/latest/developerguide/aws-managed-rule-groups-changelog.md b/waf/latest/developerguide/aws-managed-rule-groups-changelog.md
index 7dc16074c..27e7e1749 100644
--- a//waf/latest/developerguide/aws-managed-rule-groups-changelog.md
+++ b//waf/latest/developerguide/aws-managed-rule-groups-changelog.md
@@ -20,0 +21,5 @@ Rule group and rules | Description | Date
+[Known bad inputs managed rule group](./aws-managed-rule-groups-baseline.html#aws-managed-rule-groups-baseline-known-bad-inputs)
+
+  * `ReactJSRCE_BODY`
+
+|  Updated the `ReactJSRCE_BODY` to add detection for requests matching CVE-2025-55182 - A remote code execution vulnerability in React and Next.js. | 2025-12-04