React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in version 7.13.2.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Jun 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Remix-run
Remix-run react-router Remix-run turbo-stream |
|
| Vendors & Products |
Remix-run
Remix-run react-router Remix-run turbo-stream |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in version 7.13.2. | |
| Title | React Router vulnerable to Denial of Service via reflected user input in single-fetch | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-06-02T17:31:35.579Z
Updated: 2026-06-03T13:19:02.279Z
Reserved: 2026-03-25T16:21:40.868Z
Link: CVE-2026-34077
Updated: 2026-06-03T13:18:57.644Z
Status : Received
Published: 2026-06-02T20:16:34.620
Modified: 2026-06-02T20:16:34.620
Link: CVE-2026-34077
No data.