Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33244

Опубликовано: 02 июн. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP Location header value can permit Cross-Site Scripting (XSS) in the statically generated HTML files if the redirect location comes from an untrusted source. This does not impact applications using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>). This is patched in version 7.13.2.

A flaw was found in react-router. When using Framework Mode with pre-rendering enabled, an attacker can exploit improper handling of the HTTP Location header value. This can lead to Cross-Site Scripting (XSS), allowing malicious scripts to be injected into statically generated HTML files if the redirect location originates from an untrusted source.

Отчет

This Moderate flaw in react-router affects applications using Framework Mode with pre-rendering enabled, allowing cross-site scripting (XSS). An untrusted HTTP Location header can inject malicious scripts into statically generated HTML. Red Hat products are only vulnerable if deployed with this specific configuration, as Declarative Mode and Data Mode applications are unaffected.

Меры по смягчению последствий

To mitigate this issue, Red Hat customers should ensure that applications utilizing React Router avoid Framework Mode with pre-rendering enabled, particularly when handling redirect locations from untrusted sources. If this mode is essential, strict validation and sanitization of all input used in redirect URLs are required. Applications configured with Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>) are not susceptible to this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat-openshift-console-plugin-npmFix deferred
Cryostat 4grafana-infinity-datasource-npmFix deferred
Cryostat 4react-routerFix deferred
Exploit Intelligenceexploit-intelligence-tech-preview/agent-client-rhel9Fix deferred
Gatekeeper 3gatekeeper/gatekeeper-rhel9Fix deferred
Migration Toolkit for Applications 8mta/mta-ui-rhel8Fix deferred
Migration Toolkit for Applications 8mta/mta-ui-rhel9Fix deferred
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Fix deferred
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Fix deferred
Migration Toolkit for Virtualizationmtv-candidate/mtv-console-plugin-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2484045react-router: React Router: Cross-Site Scripting (XSS) via improper HTTP Location header neutralization

EPSS

Процентиль: 4%
0.00144
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
2 месяца назад

React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` header value can permit Cross-Site Scripting (XSS) in the statically generated HTML files if the redirect location comes from an untrusted source. This does not impact applications using Declarative Mode (`<BrowserRouter>`) or Data Mode (`createBrowserRouter/<RouterProvider>`). This is patched in version 7.13.2.

CVSS3: 5.4
github
2 месяца назад

React Router has stored XSS via unescaped Location header in prerendered redirect HTML

EPSS

Процентиль: 4%
0.00144
Низкий

5.4 Medium

CVSS3