Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

react-router — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in react-router, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumeration vulnerabilities associated with the react-router package developed by Remix Software. It serves as a centralized resource for tracking security issues specific to this popular React routing library used in modern web applications. The collection encompasses a wide range of vulnerability types, including cross-site scripting, path traversal, and denial-of-service risks that have been reported within the react-router ecosystem. The data covers historical entries from the initial public release of the library through the present day, ensuring comprehensive coverage of both past and current security advisories. This timeframe allows users to analyze long-term trends and see how security practices have evolved with each major version release. By reviewing this curated dataset, users can effectively track vendor advisories issued by Remix Software and the broader community. It enables developers to understand the specific manifestations of a given weakness class within the context of react-router’s codebase. Furthermore, individuals can look up the product’s vulnerability history to assess risk exposure before upgrading or deploying specific versions in production environments. This information supports informed decision-making regarding patch management, dependency updates, and overall application security posture without relying on fragmented sources.

Vendor: remix-run

CVE ID Title CVSS Severity Published
CVE-2026-53669 React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass) CWE-601 5.1 Medium 2026-07-27
CVE-2026-55685 React Router: Unauthenticated Denial of Service via Inefficient Route Matching CWE-400 8.7 High 2026-07-27
CVE-2026-53668 React Router: Open redirect can lead to XSS CWE-601 6.9 Medium 2026-07-27
CVE-2026-53667 React Router: Cross-site Scripting is Possible due to Missing RSCErrorHandler Protocol Validation (Incomplete fix for CVE-2026-53667) CWE-79 6.9 Medium 2026-07-27
CVE-2026-53666 React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration CWE-470 6.1 Medium 2026-07-27
CVE-2026-53663 React Router: `handleDocumentRequest` CSRF check covers `POST` only; PUT/PATCH/DELETE bypass CWE-352 3.1 Low 2026-06-22
CVE-2026-42342 React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint CWE-400 7.5 High 2026-06-02
CVE-2026-42211 React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE CWE-502 8.1 High 2026-06-02
CVE-2026-40181 React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation CWE-601 6.6 Medium 2026-06-02
CVE-2026-34077 React Router vulnerable to Denial of Service via reflected user input in single-fetch CWE-770 7.5 High 2026-06-02
CVE-2026-33245 React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets CWE-79 8.0 High 2026-06-02
CVE-2026-33244 React Router has stored XSS via unescaped Location header in prerendered redirect HTML CWE-79 5.4 Medium 2026-06-02
CVE-2026-22030 React Router has CSRF issue in Action/Server Action Request Processing CWE-346 6.5 Medium 2026-01-10
CVE-2026-22029 React Router vulnerable to XSS via Open Redirects CWE-79 8.0 High 2026-01-10
CVE-2026-21884 React Router SSR XSS in ScrollRestoration CWE-79 8.2 High 2026-01-10
CVE-2025-61686 React Router has Path Traversal in File Session Storage CWE-22 9.1 Critical 2026-01-10
CVE-2025-59057 React Router has XSS Vulnerability CWE-79 7.6 High 2026-01-10
CVE-2025-68470 React Router has unexpected external redirect via untrusted paths CWE-601 6.5 Medium 2026-01-10
CVE-2025-43865 React Router allows pre-render data spoofing on React-Router framework mode CWE-345 8.2 High 2025-04-25
CVE-2025-43864 React Router allows a DoS via cache poisoning by forcing SPA mode CWE-755 7.5 High 2025-04-25
CVE-2025-31137 Remix and React Router allow URL manipulation via Host / X-Forwarded-Host headers CWE-444 5.3 - 2025-04-01

All 21 known CVE vulnerabilities affecting react-router with full Chinese analysis, references, and POCs where available.