VendorsShopifyreact-routerall versions
Vulnerabilities

Shopify React-router

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2026-55685
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
Published 2026-07-27 · Analyzed
8.7EPSS 0.007
CVE-2026-21884
React Router SSR XSS in ScrollRestoration
Published 2026-01-10 · Modified
8.2EPSS 0.005
CVE-2026-42211
React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE
Published 2026-06-02 · Analyzed
8.1EPSS 0.006
CVE-2026-22029
React Router vulnerable to XSS via Open Redirects
Published 2026-01-10 · Modified
8.0EPSS 0.009
CVE-2026-33245
React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets
Published 2026-06-02 · Analyzed
8.0EPSS 0.002
CVE-2025-59057
React Router has XSS Vulnerability
Published 2026-01-10 · Modified
7.6EPSS 0.005
CVE-2026-42342
React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint
Published 2026-06-02 · Analyzed
7.5EPSS 0.005
CVE-2026-34077
React Router vulnerable to Denial of Service via reflected user input in single-fetch
Published 2026-06-02 · Analyzed
7.5EPSS 0.005
CVE-2026-53667
React Router: Cross-site Scripting is Possible due to Missing RSCErrorHandler Protocol Validation (Incomplete fix for CVE-2026-53667)
Published 2026-07-27 · Analyzed
6.9EPSS 0.004
CVE-2026-53668
React Router: Open redirect can lead to XSS
Published 2026-07-27 · Analyzed
6.9EPSS 0.003
CVE-2026-40181
React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation
Published 2026-06-02 · Analyzed
6.6EPSS 0.003
CVE-2025-68470
React Router has unexpected external redirect via untrusted paths
Published 2026-01-10 · Analyzed
6.5EPSS 0.005
CVE-2026-22030
React Router has CSRF issue in Action/Server Action Request Processing
Published 2026-01-10 · Analyzed
6.5EPSS 0.002
CVE-2026-53666
React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
Published 2026-07-27 · Analyzed
6.1EPSS 0.004
CVE-2026-53669
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
Published 2026-07-27 · Analyzed
6.1EPSS 0.003
CVE-2026-33244
React Router has stored XSS via unescaped Location header in prerendered redirect HTML
Published 2026-06-02 · Analyzed
5.4EPSS 0.002