CVE-2026-34077

React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in version 7.13.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:*
cpe:2.3:a:turbo-stream:turbo_stream:*:*:*:*:*:node.js:*:*

History

04 Jun 2026, 18:45

Type Values Removed Values Added
CPE cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:*
cpe:2.3:a:turbo-stream:turbo_stream:*:*:*:*:*:node.js:*:*
References () https://github.com/remix-run/react-router/security/advisories/GHSA-rxv8-25v2-qmq8 - () https://github.com/remix-run/react-router/security/advisories/GHSA-rxv8-25v2-qmq8 - Vendor Advisory
First Time Turbo-stream turbo Stream
Shopify
Turbo-stream
Shopify react-router

02 Jun 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-02 20:16

Updated : 2026-06-04 18:45


NVD link : CVE-2026-34077

Mitre link : CVE-2026-34077

CVE.ORG link : CVE-2026-34077


JSON object : View

Products Affected

turbo-stream

  • turbo_stream

shopify

  • react-router
CWE
CWE-770

Allocation of Resources Without Limits or Throttling