PT-2026-45828 · Remix+1 · Remix+1
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
React Router versions 7.7.0 through 7.13.1
React Router versions prior to 7.14.0
Remix versions 2.9.0 and later
Description
Two distinct issues were identified. First, a client-side Cross-Site Scripting (XSS) flaw exists in the handling of redirects within the unstable React Server Components (RSC) APIs when redirects originate from untrusted sources. Second, a Denial of Service (DoS) condition can occur in Framework Mode and Remix with Single Fetch enabled, where the serialization algorithm becomes a bottleneck when encoding specific data types into server responses. This does not affect applications using Declarative Mode (
<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>).Recommendations
Update React Router versions 7.7.0 through 7.13.1 to version 7.13.2.
Update React Router versions prior to 7.14.0 to version 7.14.0 or later.
Update Remix versions 2.9.0 and later to a version that resolves the serialization bottleneck.
Exploit
Fix
DoS
RCE
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
React Router
Remix