VulnSea

react-router has 7 CVEs on record. Disclosure cadence is accelerating: 5 in the last 90 days against 2 in the 90 before. The busiest recent month was July 2026 with 5. The median CVSS is 6.1 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-79 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.1
Publish → KEV
Last 90 days
5 prev 2

Products

  • react-router 7
7
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

react-router vulnerabilities

CVEs affecting react-router, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

GHSA-qwww-vcr4-c8h2High
2mo ago

React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response

React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response

Twilightreact-router · react-routervia GHSA
CVE-2026-53666Medium· 6.1
2mo ago

React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration

React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration

Sunlitreact-router · react-routerEPSS 0.30%via GHSA
CVE-2026-53667Medium· 6.9
2mo ago

React Router: RSCErrorHandler Missing Protocol Validation (XSS)

React Router: RSCErrorHandler Missing Protocol Validation (XSS)

Sunlitreact-router · react-routerEPSS 0.20%via GHSA
CVE-2026-53668Medium· 6.9
2mo ago

React Router: Open redirect leading to XSS

React Router: Open redirect leading to XSS

Sunlitreact-router · react-routerEPSS 0.28%via GHSA
CVE-2026-53669Medium
2mo ago

React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)

React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)

Sunlitreact-router · react-routerEPSS 0.23%via GHSA
CVE-2026-53663Low· 3.1
3mo ago

React Router: Potential CSRF via PUT/PATCH/DELETE document requests

React Router: Potential CSRF via PUT/PATCH/DELETE document requests

Sunlitreact-router · react-routerEPSS 0.15%via GHSA
CVE-2026-33244Medium· 5.4
3mo ago

React Router has stored XSS via unescaped Location header in prerendered redirect HTML

React Router has stored XSS via unescaped Location header in prerendered redirect HTML

Sunlitreact-router · react-routerEPSS 0.14%via GHSA
react-router vulnerabilities (CVEs) · VulnSea