React Router
Vendor:
First CVE: Jan 10, 2026 · Active for under a year
11
Total CVEs
More Total CVEs than 89% of tracked products
11.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact React Router over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 10, 2026
6 months ago
Most Recent CVE
Jun 2, 2026
52 days ago
CVE Severity & Scoring
React Router11 CVEs
55%
45%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (81.8%)
High2 (18.2%)
Unknown0 (0.0%)
User Interaction
None4 (36.4%)
Unknown0 (0.0%)
Required7 (63.6%)
Privileges Required
Low3 (27.3%)
High0 (0.0%)
None8 (72.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42211HIGH React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unauthorized remote code execution ( | Jun 2, 2026 | 8.1 | 36 | NO | NO |
CVE-2026-34077HIGH React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross- | Jun 2, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-42342HIGH React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can c | Jun 2, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-21884HIGH React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's <ScrollResto | Jan 10, 2026 | 8.2 | 31 | NO | NO |
CVE-2025-59057HIGH React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router | Jan 10, 2026 | 7.6 | 30 | NO | NO |
CVE-2026-22029MEDIUM React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects | Jan 10, 2026 | 6.1 | 27 | NO | NO |
CVE-2026-40181MEDIUM React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigger an open redirect to an exter | Jun 2, 2026 | 6.1 | 26 | NO | NO |
CVE-2026-33245MEDIUM React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross- | Jun 2, 2026 | 4.7 | 26 | NO | NO |
CVE-2026-33244MEDIUM React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` header va | Jun 2, 2026 | 5.4 | 25 | NO | NO |
CVE-2026-22030MEDIUM React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, React Router (or Remix v2) is vulnerable to CSRF at | Jan 10, 2026 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For React Router
Top CWEs
Versions
No cataloged versions.