Where
-Infinity
0

IBM Engineering AI HubReact Router vulnerable to DoS via unbounded path expansion in __manifest endpoint

Risk 43
Severity
7.5
First published (updated )

IBM Engineering AI HubReact Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE

Risk 75
Severity
8.1
First published (updated )

npm/react-routerReact Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation

Risk 40
Severity
6.6
First published (updated )

IBM Engineering AI HubReact Router vulnerable to Denial of Service via reflected user input in single-fetch

Risk 43
Severity
7.5
First published (updated )

npm/react-routerReact Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets

Risk 58
Severity
8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/react-routerReact Router has stored XSS via unescaped Location header in prerendered redirect HTML

Risk 34
Severity
5.4
First published (updated )

npm/@remix-run/reactXSS

Risk 33
Severity
7
First published (updated )

npm/@remix-run/reactXSS

Risk 33
Severity
7
First published (updated )

npm/@remix-run/routerReact Router is a router for React. In @remix-run/router version prior to 1.23.2. and react-router 7…

Risk 33
Severity
7
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203