CVE-2026-42342
- EPSS 0.3%
- Veröffentlicht 02.06.2026 18:23:02
- Zuletzt bearbeitet 04.06.2026 19:00:32
React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can consume disproportionate server resources via unbounded path expansion ...
CVE-2026-42211
- EPSS 0.42%
- Veröffentlicht 02.06.2026 18:18:46
- Zuletzt bearbeitet 04.06.2026 18:50:38
React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unauthorized remote code execution (RCE) through external requests. This attack requires the application c...
CVE-2026-40181
- EPSS 0.16%
- Veröffentlicht 02.06.2026 17:55:09
- Zuletzt bearbeitet 04.06.2026 18:46:47
React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigger an open redirect to an external domain due to path values starting with // being reinterpreted as ...
CVE-2026-34077
- EPSS 0.29%
- Veröffentlicht 02.06.2026 17:31:35
- Zuletzt bearbeitet 04.06.2026 18:45:52
React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if red...
CVE-2026-33245
- EPSS 0.19%
- Veröffentlicht 02.06.2026 17:14:50
- Zuletzt bearbeitet 04.06.2026 18:43:39
React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if red...
CVE-2026-33244
- EPSS 0.14%
- Veröffentlicht 02.06.2026 16:59:31
- Zuletzt bearbeitet 03.06.2026 16:54:00
React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` header value can permit Cross-Site Scripting (XSS) in the statically generated ...
CVE-2026-22030
- EPSS 0.13%
- Veröffentlicht 10.01.2026 02:42:44
- Zuletzt bearbeitet 05.02.2026 20:51:29
React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, React Router (or Remix v2) is vulnerable to CSRF attacks on document POST requests to UI routes when using server-side ro...
CVE-2026-22029
- EPSS 0.33%
- Veröffentlicht 10.01.2026 02:42:32
- Zuletzt bearbeitet 02.06.2026 17:16:27
React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or ...
CVE-2026-21884
- EPSS 0.37%
- Veröffentlicht 10.01.2026 02:41:44
- Zuletzt bearbeitet 30.01.2026 18:19:22
React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's <ScrollRestoration> API in Framework Mode when using the getKey/storageKey props d...
CVE-2025-59057
- EPSS 0.32%
- Veröffentlicht 10.01.2026 02:40:25
- Zuletzt bearbeitet 30.01.2026 18:19:56
React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating script:ld+json...