Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-21884

Опубликовано: 10 янв. 2026
Источник: redhat
CVSS3: 8.2

Описание

React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's API in Framework Mode when using the getKey/storageKey props during Server-Side Rendering which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the keys. There is no impact if server-side rendering in Framework Mode is disabled, or if Declarative Mode () or Data Mode (createBrowserRouter/) is being used. This issue has been patched in @remix-run/react version 2.17.3 and react-router version 7.12.0.

A cross site scripting flaw has been discovered in the npm react-router package. The cross site scripting (XSS) vulnerability exists in in React Router's API in Framework Mode when using the getKey/storageKey props during Server-Side Rendering which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the keys.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of Kueuekueue/kueue-must-gather-rhel9Not affected
Red Hat Build of Kueuekueue/kueue-operator-bundleNot affected
Red Hat Build of Kueuekueue/kueue-rhel9Not affected
Red Hat Build of Kueuekueue/kueue-rhel9-operatorNot affected
Red Hat Enterprise Linux 10ipaNot affected
Red Hat Enterprise Linux 9ipaNot affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-gen-ai-rhel9Affected
Red Hat Ansible Automation Platform 2.6 for RHEL 9automation-platform-uiFixedRHSA-2026:395806.03.2026
Red Hat Ansible Automation Platform 2.6ansible-automation-platform-26/gateway-rhel9FixedRHSA-2026:396006.03.2026
Red Hat OpenShift AI 2.25rhoai/odh-dashboard-rhel9FixedRHSA-2026:378204.03.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2428421react-router: @remix-run/react: React Router SSR XSS in ScrollRestoration

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
nvd
3 месяца назад

React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's <ScrollRestoration> API in Framework Mode when using the getKey/storageKey props during Server-Side Rendering which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the keys. There is no impact if server-side rendering in Framework Mode is disabled, or if Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>) is being used. This issue has been patched in @remix-run/react version 2.17.3 and react-router version 7.12.0.

CVSS3: 8.2
github
3 месяца назад

React Router SSR XSS in ScrollRestoration

8.2 High

CVSS3