npm

react-router

View on npm registry
20 Total advisories
20 Vulnerabilities
0 Malware

Dependency scanning

Check whether react-router is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
npm

CVE-2026-53669

React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)

UNKNOWN
npm

CVE-2026-55685

React Router: Unauthenticated Denial of Service via Inefficient Route Matching

LOW 3.1
npm

CVE-2026-53663

React Router: Potential CSRF via PUT/PATCH/DELETE document requests

UNKNOWN
npm

CVE-2026-40181

React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation

UNKNOWN
npm

GHSA-qwww-vcr4-c8h2

React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response

MEDIUM 6.9
npm

CVE-2026-53667

React Router: RSCErrorHandler Missing Protocol Validation (XSS)

MEDIUM 6.1
npm

CVE-2026-53666

React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration

HIGH 7.5
npm

CVE-2026-42342

React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint

HIGH 8.1
npm

CVE-2026-42211

React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE

MEDIUM 6.5
npm

CVE-2026-22030

React Router has CSRF issue in Action/Server Action Request Processing

HIGH 7.6
npm

CVE-2025-59057

React Router has XSS Vulnerability

MEDIUM 5.4
npm

CVE-2026-33244

React Router has stored XSS via unescaped Location header in prerendered redirect HTML

HIGH 8.2
npm

CVE-2026-21884

React Router SSR XSS in ScrollRestoration

MEDIUM 6.9
npm

CVE-2026-53668

React Router: Open redirect leading to XSS

HIGH 7.5
npm

CVE-2026-34077

React Router vulnerable to Denial of Service via reflected user input in single-fetch

HIGH 8.0
npm

CVE-2026-33245

React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets

HIGH 8.0
npm

CVE-2026-22029

React Router vulnerable to XSS via Open Redirects

MEDIUM 6.5
npm

CVE-2025-68470

React Router has unexpected external redirect via untrusted paths

HIGH 8.2
npm

CVE-2025-43865

React Router allows pre-render data spoofing on React-Router framework mode

HIGH 7.5
npm

CVE-2025-43864

React Router allows a DoS via cache poisoning by forcing SPA mode

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes