Feed/CVE-2026-40181
CVE-2026-40181MEDIUMCVSS 0.0

React Router's same-origin redirect with path starting // causes open redirect via protocol-relative URL reinterpretation

Published Jun 3, 2026·Updated Aug 4, 2026

NVD Description

Certain URLs passed to the `redirect` function can trigger an open redirect to an external domain depending on the level of validation done by the application prior to returning the `redirect`. > [!NOTE] > This does not impact your React Router application if you are using [Declarative Mode](https://reactrouter.com/start/modes#declarative) (`<BrowserRouter>`)

Affected Packages (2)

react-routerNPM
From 7.0.0
Fixed in 7.14.1
@remix-run/routerNPM
From 1.3.0
Fixed in 1.23.3

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free