Security Advisories for react-router in npm
High
11 days ago
React Router vulnerable to Denial of Service via reflected user input in single-fetch
npm
turbo-stream, react-router
High
12 days ago
React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint
npm
@remix-run/server-runtime, react-router
High
12 days ago
React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE
npm
react-router
Moderate
12 days ago
React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation
npm
react-router
High
12 days ago
React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets
npm
react-router
Moderate
12 days ago
React Router has stored XSS via unescaped Location header in prerendered redirect HTML
npm
react-router
Moderate
5 months ago
React Router has CSRF issue in Action/Server Action Request Processing
npm
@remix-run/server-runtime, react-router
High
5 months ago
React Router vulnerable to XSS via Open Redirects
npm
@remix-run/router, react-router
Moderate
5 months ago
React Router has unexpected external redirect via untrusted paths
npm
react-router
High
about 1 year ago
React Router allows pre-render data spoofing on React-Router framework mode
npm
react-router
High
about 1 year ago
React Router allows a DoS via cache poisoning by forcing SPA mode
npm
react-router
Potential
High
about 1 year ago
Remix and React Router allow URL manipulation via Host / X-Forwarded-Host headers
npm
@remix-run/express, @react-router/express