CVE-2026-34077

React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in version 7.13.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:*
cpe:2.3:a:turbo-stream:turbo_stream:*:*:*:*:*:node.js:*:*

History

22 Jul 2026, 19:10

Type Values Removed Values Added
Summary
  • (es) React Router es un router para React. En las versiones 7.7.0 a la 7.13.1, al usar las API inestables de React Server Components (RSC) de React Router, existe una potencial vulnerabilidad de Cross-Site Scripting (XSS) del lado del cliente en el manejo de redirecciones de RSC si las redirecciones provienen de fuentes no confiables. Esto no tiene impacto en las aplicaciones que no están usando las API inestables de RSC en React Router. Esto está parcheado en la versión 7.13.2.

04 Jun 2026, 18:45

Type Values Removed Values Added
CPE cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:*
cpe:2.3:a:turbo-stream:turbo_stream:*:*:*:*:*:node.js:*:*
First Time Turbo-stream turbo Stream
Shopify
Turbo-stream
Shopify react-router
References () https://github.com/remix-run/react-router/security/advisories/GHSA-rxv8-25v2-qmq8 - () https://github.com/remix-run/react-router/security/advisories/GHSA-rxv8-25v2-qmq8 - Vendor Advisory

02 Jun 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-02 20:16

Updated : 2026-07-22 19:10


NVD link : CVE-2026-34077

Mitre link : CVE-2026-34077

CVE.ORG link : CVE-2026-34077


JSON object : View

Products Affected

turbo-stream

  • turbo_stream

shopify

  • react-router
CWE
CWE-770

Allocation of Resources Without Limits or Throttling