PT-2026-45828 · Remix+1 · Remix+1

·

CVE-2026-34077

·

Published

2026-06-02

·

Updated

2026-06-27

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions React Router versions 7.7.0 through 7.13.1 React Router versions prior to 7.14.0 Remix versions 2.9.0 and later
Description Two distinct issues were identified. First, a client-side Cross-Site Scripting (XSS) flaw exists in the handling of redirects within the unstable React Server Components (RSC) APIs when redirects originate from untrusted sources. Second, a Denial of Service (DoS) condition can occur in Framework Mode and Remix with Single Fetch enabled, where the serialization algorithm becomes a bottleneck when encoding specific data types into server responses. This does not affect applications using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>).
Recommendations Update React Router versions 7.7.0 through 7.13.1 to version 7.13.2. Update React Router versions prior to 7.14.0 to version 7.14.0 or later. Update Remix versions 2.9.0 and later to a version that resolves the serialization bottleneck.

Exploit

Fix

DoS

RCE

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34077
GHSA-RXV8-25V2-QMQ8
OPENSUSE-SU-2026:11128-1

Affected Products

React Router
Remix