pkg:npm/react-router
共 13 筆 CVEHIGH9MEDIUM3
✅ 檢查你的版本
所有已知漏洞
- >= 7.0.0, < 7.12.0
- >= 7.0.0-pre.0, < 7.5.2
- HIGH8.1CVE-2026-42211React Router's vendored turbo-stream v2 allows arbitrary constructor invocation via TYPE_ERROR deserialization leading to Unauth RCE>= 7.0.0, < 7.14.2
- HIGH8.0CVE-2026-33245React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets>= 7.7.0, < 7.13.2
- >= 7.0.0, < 7.12.0
- >= 7.0.0, < 7.9.0
- HIGH7.5CVE-2026-34077React Router vulnerable to Denial of Service via reflected user input in single-fetch>= 7.0.0, < 7.14.0
- HIGH7.5CVE-2026-42342React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint>= 7.0.0, < 7.15.0
- >= 7.2.0, < 7.5.2
- >= 7.0.0, < 7.12.0
- >= 6.0.0, < 6.30.2
- MEDIUM5.4CVE-2026-33244React Router has stored XSS via unescaped Location header in prerendered redirect HTML>= 7.5.1, < 7.13.2
- —CVE-2026-40181React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation>= 7.0.0, < 7.14.1