React-router
24 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for React-router, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
React-router CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 3 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 6 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 2 |
| 2026-06 | 7 |
| 2026-07 | 6 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 24 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High12
- Medium8
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting React-router.
- CVE-2026-53669React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)6.1
- CVE-2026-55685React Router: Unauthenticated Denial of Service via Inefficient Route Matching7.5
- CVE-2026-53668React Router: Open redirect can lead to XSS6.9
- CVE-2026-53667React Router: Cross-site Scripting is Possible due to Missing RSCErrorHandler Protocol Validation (Incomplete fix for CVE-2026-53667)6.9
- CVE-2026-53666React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration6.1
- GHSA-qwww-vcr4-c8h2React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response—
- CVE-2026-53663React Router: `handleDocumentRequest` CSRF check covers `POST` only; PUT/PATCH/DELETE bypass3.1
- CVE-2026-42342React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint7.5
- CVE-2026-42211React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE8.1
- CVE-2026-40181React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation6.1
- CVE-2026-34077React Router vulnerable to Denial of Service via reflected user input in single-fetch7.5
- CVE-2026-33245React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets8.0
- CVE-2026-33244React Router has stored XSS via unescaped Location header in prerendered redirect HTML5.4
- CVE-2026-45321Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys9.6
- CVE-2026-42349Clerk: Authorization bypass when combining organization, billing, or reverification checks8.1
Product grouping is registry-driven, with AI assist and human review. How it works