CVE-2026-22030
- EPSS 0.02%
- Veröffentlicht 10.01.2026 02:42:44
- Zuletzt bearbeitet 05.02.2026 20:51:29
React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, React Router (or Remix v2) is vulnerable to CSRF attacks on document POST requests to UI routes when using server-side ro...
CVE-2026-22029
- EPSS 0.02%
- Veröffentlicht 10.01.2026 02:42:32
- Zuletzt bearbeitet 10.02.2026 19:36:31
React Router is a router for React. In @remix-run/router version prior to 1.23.2. and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or...
CVE-2026-21884
- EPSS 0.02%
- Veröffentlicht 10.01.2026 02:41:44
- Zuletzt bearbeitet 30.01.2026 18:19:22
React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's <ScrollRestoration> API in Framework Mode when using the getKey/storageKey props d...
CVE-2025-59057
- EPSS 0.02%
- Veröffentlicht 10.01.2026 02:40:25
- Zuletzt bearbeitet 30.01.2026 18:19:56
React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating script:ld+json...
CVE-2025-68470
- EPSS 0.03%
- Veröffentlicht 10.01.2026 02:39:41
- Zuletzt bearbeitet 30.01.2026 18:20:54
React Router is a router for React. In versions 6.0.0 through 6.30.1 and 7.0.0 through 7.9.5, an attacker-supplied path can be crafted so that when a React Router application navigates to it via navigate(), <Link>, or redirect(), the app performs a n...