CVE-2026-34077

React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in version 7.13.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:*
cpe:2.3:a:turbo-stream:turbo_stream:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-06-02 20:16

Updated : 2026-07-22 19:10


NVD link : CVE-2026-34077

Mitre link : CVE-2026-34077

CVE.ORG link : CVE-2026-34077


JSON object : View

Products Affected

shopify

  • react-router

turbo-stream

  • turbo_stream
CWE
CWE-770

Allocation of Resources Without Limits or Throttling