Remix-run
6 CVEs tracked since 2026. Since Jan 2026, none of them reached CISA KEV.
Remix-run CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-01 | 6 | 0 |
Products
The products that kept showing up in Remix-run's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Remix-run.
- CVE-2026-53669React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)6.1
- CVE-2026-55685React Router: Unauthenticated Denial of Service via Inefficient Route Matching7.5
- CVE-2026-53668React Router: Open redirect can lead to XSS6.9
- CVE-2026-53667React Router: Cross-site Scripting is Possible due to Missing RSCErrorHandler Protocol Validation (Incomplete fix for CVE-2026-53667)6.9
- CVE-2026-53666React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration6.1
- CVE-2026-53663React Router: `handleDocumentRequest` CSRF check covers `POST` only; PUT/PATCH/DELETE bypass3.1
- CVE-2026-42342React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint7.5
- CVE-2026-42211React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE8.1
- CVE-2026-40181React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation6.1
- CVE-2026-34077React Router vulnerable to Denial of Service via reflected user input in single-fetch7.5
- CVE-2026-33245React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets8.0
- CVE-2026-33244React Router has stored XSS via unescaped Location header in prerendered redirect HTML5.4
- CVE-2026-22030React Router has CSRF issue in Action/Server Action Request Processing6.5
- CVE-2026-22029React Router vulnerable to XSS via Open Redirects8.0
- CVE-2026-21884React Router SSR XSS in ScrollRestoration8.2
The record
- Peak rank
- #159 in Jan 2026
- Busiest month shown
- Jan 2026, 6 CVEs
- Months with a KEV entry
- 0 since Jan 2026
- Monthly snapshots
- 1 since 2026