20 Total advisories
20 Vulnerabilities
0 Malware
Dependency scanning
Check whether react-router is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-53669
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
UNKNOWN
CVE-2026-55685
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
LOW 3.1
CVE-2026-53663
React Router: Potential CSRF via PUT/PATCH/DELETE document requests
UNKNOWN
CVE-2026-40181
React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation
UNKNOWN
GHSA-qwww-vcr4-c8h2
React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response
MEDIUM 6.9
CVE-2026-53667
React Router: RSCErrorHandler Missing Protocol Validation (XSS)
MEDIUM 6.1
CVE-2026-53666
React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
HIGH 7.5
CVE-2026-42342
React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint
HIGH 8.1
CVE-2026-42211
React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE
MEDIUM 6.5
CVE-2026-22030
React Router has CSRF issue in Action/Server Action Request Processing
HIGH 7.6
CVE-2025-59057
React Router has XSS Vulnerability
MEDIUM 5.4
CVE-2026-33244
React Router has stored XSS via unescaped Location header in prerendered redirect HTML
HIGH 8.2
CVE-2026-21884
React Router SSR XSS in ScrollRestoration
MEDIUM 6.9
CVE-2026-53668
React Router: Open redirect leading to XSS
HIGH 7.5
CVE-2026-34077
React Router vulnerable to Denial of Service via reflected user input in single-fetch
HIGH 8.0
CVE-2026-33245
React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets
HIGH 8.0
CVE-2026-22029
React Router vulnerable to XSS via Open Redirects
MEDIUM 6.5
CVE-2025-68470
React Router has unexpected external redirect via untrusted paths
HIGH 8.2
CVE-2025-43865
React Router allows pre-render data spoofing on React-Router framework mode
HIGH 7.5
CVE-2025-43864
React Router allows a DoS via cache poisoning by forcing SPA mode
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes