Shopify

React-router

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 27.07.2026 22:17:31
  • Zuletzt bearbeitet 03.08.2026 13:56:59

React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in <Link> and useNavigate. This issue is a follow up to CVE-2025-68470 and has been fixed in version 7.18.0.

  • EPSS 0.7%
  • Veröffentlicht 27.07.2026 21:45:57
  • Zuletzt bearbeitet 03.08.2026 13:56:02

React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times. This issue is a follow up to CVE...

  • EPSS 0.34%
  • Veröffentlicht 27.07.2026 21:42:17
  • Zuletzt bearbeitet 03.08.2026 14:13:34

React Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable to XSS. An attacker could craft a malicious link that redirects users to an unexpected external site...

  • EPSS 0.35%
  • Veröffentlicht 27.07.2026 21:21:16
  • Zuletzt bearbeitet 03.08.2026 13:58:50

React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up to CVE-2026-53667, and only affects consuming applicat...

  • EPSS 0.42%
  • Veröffentlicht 27.07.2026 21:14:49
  • Zuletzt bearbeitet 03.08.2026 14:04:25

React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for an attacker ...

  • EPSS 0.3%
  • Veröffentlicht 02.06.2026 18:23:02
  • Zuletzt bearbeitet 21.07.2026 19:10:00

React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can consume disproportionate server resources via unbounded path expansion ...

  • EPSS 0.42%
  • Veröffentlicht 02.06.2026 18:18:46
  • Zuletzt bearbeitet 21.07.2026 19:10:00

React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unauthorized remote code execution (RCE) through external requests. This attack requires the application c...

  • EPSS 0.16%
  • Veröffentlicht 02.06.2026 17:55:09
  • Zuletzt bearbeitet 04.08.2026 22:17:14

React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigger an open redirect to an external domain due to path values starting with // being reinterpreted as ...

  • EPSS 0.29%
  • Veröffentlicht 02.06.2026 17:31:35
  • Zuletzt bearbeitet 22.07.2026 19:10:00

React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if red...

  • EPSS 0.19%
  • Veröffentlicht 02.06.2026 17:14:50
  • Zuletzt bearbeitet 22.07.2026 19:10:00

React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if red...