<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – React (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/react.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/react-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – React (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:32 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-42342 – React Router is a router for React. In versions 7.0.0 through 7.14.x of react-ro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42342</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42342</strong></p>
  <p>React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can consume disproportionate server resources via unbounded path expansion in the __manifest endpoint, resulting in response time degradation and/or service unavailability for end users. This affects React Router Framework M…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42342">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42211 – React Router is a router for React. In versions 7.0.0 through 7.14.1, when using...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42211</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42211</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42211</strong></p>
  <p>React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unauthorized remote code execution (RCE) through external requests. This attack requires the application code to have an existing prototype pollution vulnerability, which can then be leveraged in a 2-step attack where the second step triggers unauthorized…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42211">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34077 – React Router is a router for React. In versions 7.7.0 through 7.13.1, when using...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34077</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34077</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34077</strong></p>
  <p>React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in ve…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34077">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33245 – React Router is a router for React. In versions 7.7.0 through 7.13.1, when using...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33245</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33245</strong></p>
  <p>React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in ve…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7459 – The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPres...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7459</guid>
    <pubDate>Sat, 30 May 2026 10:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7459</strong></p>
  <p>The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subscriber+) account takeover in all versions up to, and including, 5.26.0 via the event reaction endpoints (react_to_event() / unreact_to_event()). The endpoints register get_items_permissions_check() as their permission_callback, which only verifies the requester is logged in and do…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44483 – RVF (formerly Remix Validated Form) provides easy form validation and state mana...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44483</guid>
    <pubDate>Wed, 27 May 2026 17:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44483</strong></p>
  <p>RVF (formerly Remix Validated Form) provides easy form validation and state management for React. From 6.0.0 to before 6.0.4 and 7.0.2, setPath in @rvf/set-get (used by @rvf/core to flatten incoming form data into a nested object) does not block the keys __proto__, constructor, or prototype when walking a path. Because field names in submitted form data are passed directly to setPath via preproce…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45109 – Next.js is a React framework for building full-stack web applications. From 15.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45109</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45109</guid>
    <pubDate>Wed, 13 May 2026 18:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45109</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45109">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44579 – Next.js is a React framework for building full-stack web applications. From  to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44579</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44579</guid>
    <pubDate>Wed, 13 May 2026 18:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44579</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From  to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections open…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44579">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44578 – Next.js is a React framework for building full-stack web applications. From 13.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44578</guid>
    <pubDate>Wed, 13 May 2026 18:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44578</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44575 – Next.js is a React framework for building full-stack web applications. From 15.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44575</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44575</guid>
    <pubDate>Wed, 13 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44575</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted .rsc and segment-prefetch URLs can resolve to the…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44575">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44574 – Next.js is a React framework for building full-stack web applications. From 15.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44574</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44574</guid>
    <pubDate>Wed, 13 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44574</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected c…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44574">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44573 – Next.js is a React framework for building full-stack web applications. From 12.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44573</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44573</guid>
    <pubDate>Wed, 13 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44573</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<buildId>/<page>.json requests. In affected configurations, middleware does not run for the unprefixed…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44573">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23870 – A denial of service vulnerability could be triggered by sending specially crafte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23870</guid>
    <pubDate>Wed, 06 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23870</strong></p>
  <p>A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23870">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41679 – Paperclip is a Node.js server and React UI that orchestrates a team of AI agents...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41679</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41679</guid>
    <pubDate>Thu, 23 Apr 2026 02:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41679</strong></p>
  <p>Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration. No user interaction, no credentials, just the target's address. The chain consists of six API call…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41679">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41208 – Paperclip is a Node.js server and React UI that orchestrates a team of AI agents...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41208</guid>
    <pubDate>Thu, 23 Apr 2026 02:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41208</strong></p>
  <p>Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @paperclipai/server prior to 2026.416.0 contain a privilege escalation vulnerability that allows an attacker with an Agent API key to execute arbitrary OS commands on the Paperclip server host. An attacker with an agent credential can escalate privileges from the agent runtime to the Pa…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23869 – A denial of service vulnerability exists in React Server Components, affecting t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23869</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23869</guid>
    <pubDate>Wed, 08 Apr 2026 20:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23869</strong></p>
  <p>A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered by sending specially crafted HTTP requests to Server Function endpoints.The payload of the HTTP requ…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23869">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39371 – RedwoodSDK is a server-first React framework. From 1.0.0-beta.50 to 1.0.5, erver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39371</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39371</strong></p>
  <p>RedwoodSDK is a server-first React framework. From 1.0.0-beta.50 to 1.0.5, erver functions exported from "use server" files could be invoked via GET requests, bypassing their intended HTTP method. In cookie-authenticated applications, this allowed cross-site GET navigations to trigger state-changing functions, because browsers send SameSite=Lax cookies on top-level GET requests. This affected all…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-35052 – D-Tale is the combination of a Flask back-end and a React front-end to view &amp; an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35052</guid>
    <pubDate>Mon, 06 Apr 2026 18:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-35052</strong></p>
  <p>D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3.22.0, users hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. This vulnerability is fixed in 3.22.0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34456 – Reviactyl is an open-source game server management panel built using Laravel, Re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34456</guid>
    <pubDate>Wed, 01 Apr 2026 20:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34456</strong></p>
  <p>Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From version 26.2.0-beta.1 to before version 26.2.0-beta.5, a vulnerability in the OAuth authentication flow allowed automatic linking of social accounts based solely on matching email addresses. An attacker could create or control a social account (e.g., Google, GitHub, Discord) using…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27980 – Next.js is a React framework for building full-stack web applications. Starting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27980</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27980</guid>
    <pubDate>Wed, 18 Mar 2026 01:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27980</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allowing unbounded cache growth. An attacker could generate many unique image-optimization variants and exhaust disk space, causing denial of service. This is fixed…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27980">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27979 – Next.js is a React framework for building full-stack web applications. Starting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27979</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27979</guid>
    <pubDate>Wed, 18 Mar 2026 01:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27979</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, a request containing the `next-resume: 1` header (corresponding with a PPR resume request) would buffer request bodies without consistently enforcing `maxPostponedStateSize` in certain setups. The previous mitigation protected minimal-mode deployments, but equivalent non-…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27979">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30862 – Appsmith is a platform to build admin panels, internal tools, and dashboards. Pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30862</guid>
    <pubDate>Tue, 10 Mar 2026 17:40:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30862</strong></p>
  <p>Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table Widget (TableWidgetV2). The root cause is a lack of HTML sanitization in the React component rendering pipeline, allowing malicious attributes to be interpolated into the DOM. By leveraging the "Invite Users" feature, an attacker with a regular user…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23864 – Multiple denial of service vulnerabilities exist in React Server Components, aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23864</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23864</guid>
    <pubDate>Mon, 26 Jan 2026 20:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23864</strong></p>
  <p>Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack.  The vulnerabilities are triggered by sending specially crafted HTTP requests to Server Function endpoints, and could lead to server crashes, out-of-memory exceptions or excessive CPU usage; depending on the v…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23864">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22029 – React Router is a router for React. In @remix-run/router version prior to 1.23.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22029</guid>
    <pubDate>Sat, 10 Jan 2026 03:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22029</strong></p>
  <p>React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if you are creating red…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21884 – React Router is a router for React. In @remix-run/react version prior to 2.17.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21884</guid>
    <pubDate>Sat, 10 Jan 2026 03:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21884</strong></p>
  <p>React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's <ScrollRestoration> API in Framework Mode when using the getKey/storageKey props during Server-Side Rendering which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the keys. There is n…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-61686 – React Router is a router for React. In @react-router/node versions 7.0.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61686</guid>
    <pubDate>Sat, 10 Jan 2026 03:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-61686</strong></p>
  <p>React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if createFileSessionStorage() is being used from @react-router/node (or @remix-run/node/@remix-run/deno in Remix v2) with an unsigned cookie, it is possible for an attacker to cause the session to try to read/write from a loc…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59057 – React Router is a router for React. In @remix-run/react versions 1.15.0 through ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59057</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59057</guid>
    <pubDate>Sat, 10 Jan 2026 03:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59057</strong></p>
  <p>React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the tag. There is no impact if the applica…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59057">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68155 – @vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68155</guid>
    <pubDate>Tue, 16 Dec 2025 19:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68155</strong></p>
  <p>@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_findSourceMapURL` endpoint in `@vitejs/plugin-rsc` allows unauthenticated arbitrary file read during development mode. An attacker can read any file accessible to the Node.js process by sending a crafted HTTP request with a `file://` URL in the `filename` query parameter. Version 0.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67779 – It was found that the fix addressing CVE-2025-55184 in React Server Components w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67779</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67779</guid>
    <pubDate>Fri, 12 Dec 2025 00:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67779</strong></p>
  <p>It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads from HTTP requests to Server Function endpoints. This can cause an infinite loop that hangs the server process and may p…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67779">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55184 – A pre-authentication denial of service vulnerability exists in React Server Comp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55184</guid>
    <pubDate>Thu, 11 Dec 2025 20:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55184</strong></p>
  <p>A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints, which can cause an infinite…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-67489 – @vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67489</guid>
    <pubDate>Tue, 09 Dec 2025 21:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-67489</strong></p>
  <p>@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versions 0.5.5 and below are vulnerable to arbitrary remote code execution on the development server through unsafe dynamic imports in server function APIs (loadServerAction, decodeReply, decodeAction) when integrated into RSC applications that expose server function endpoints. Attackers with network access to the developm…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-55182 – A pre-authentication remote code execution vulnerability exists in React Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55182</guid>
    <pubDate>Wed, 03 Dec 2025 16:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-55182</strong></p>
  <p>A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-11953 – The Metro Development Server, which is opened by the React Native Community CLI,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11953</guid>
    <pubDate>Mon, 03 Nov 2025 17:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-11953</strong></p>
  <p>The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlle…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58047 – Volto is a React based frontend for the Plone Content Management System. In vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58047</guid>
    <pubDate>Thu, 28 Aug 2025 18:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58047</strong></p>
  <p>Volto is a React based frontend for the Plone Content Management System. In versions from 19.0.0-alpha.1 to before 19.0.0-alpha.4, 18.0.0 to before 18.24.0, 17.0.0 to before 17.22.1, and prior to 16.34.0, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL. The problem has been patched in versions 16.34.0, 17.22.1, 18.24.0, and 19.0.0-a…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55008 – The AuthKit library for React Router 7+ provides helpers for authentication and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55008</guid>
    <pubDate>Sat, 09 Aug 2025 03:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55008</strong></p>
  <p>The AuthKit library for React Router 7+ provides helpers for authentication and session management using WorkOS & AuthKit with React Router. In versions 0.6.1 and below, @workos-inc/authkit-react-router exposed sensitive authentication artifacts — specifically sealedSession and accessToken by returning them from the authkitLoader. This caused them to be rendered into the browser HTML. This issue…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54594 – react-native-bottom-tabs is a library of Native Bottom Tabs for React Native. In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54594</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54594</guid>
    <pubDate>Wed, 06 Aug 2025 00:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54594</strong></p>
  <p>react-native-bottom-tabs is a library of Native Bottom Tabs for React Native. In versions 0.9.2 and below, the github/workflows/release-canary.yml GitHub Actions repository workflow improperly used the pull_request_target event trigger, which allowed for untrusted code from a forked pull request to be executed in a privileged context. An attacker could create a pull request containing a malicious…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54594">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36850 – An information disclosure vulnerability exits in Sitecore JSS React Sample Appli...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36850</guid>
    <pubDate>Fri, 25 Jul 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36850</strong></p>
  <p>An information disclosure vulnerability exits in Sitecore JSS React Sample Application 11.0.0 - 14.0.1 that may cause page content intended for one user to be shown to another user.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49826 – Next.js is a React framework for building full-stack web applications. From vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49826</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49826</guid>
    <pubDate>Thu, 03 Jul 2025 21:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49826</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From versions 15.0.4-canary.51 to before 15.1.8, a cache poisoning bug leading to a Denial of Service (DoS) condition was found in Next.js. This issue does not impact customers hosted on Vercel. Under certain conditions, this issue may allow a HTTP 204 response to be cached for static pages, leading to the 204 response being s…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49826">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-45001 – react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-45001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-45001</guid>
    <pubDate>Mon, 09 Jun 2025 17:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-45001</strong></p>
  <p>react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaintext in the compiled native binary. Attackers can extract these secrets using basic static analysis tools.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49006 – Wasp (Web Application Specification) is a Rails-like framework for React, Node.j...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49006</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49006</guid>
    <pubDate>Mon, 09 Jun 2025 13:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49006</strong></p>
  <p>Wasp (Web Application Specification) is a Rails-like framework for React, Node.js, and Prisma. Prior to version 0.16.6, Wasp authentication has a vulnerability in the OAuth authentication implementation (affecting only Keycloak with a specific config). Wasp currently lowercases OAuth user IDs before storing / fetching them. This behavior violates OAuth and OpenID Connect specifications and can re…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49006">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43865 – React Router is a router for React. In versions on the 7.0 branch prior to versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43865</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43865</guid>
    <pubDate>Fri, 25 Apr 2025 01:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43865</strong></p>
  <p>React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding a header to the request. This allows to completely spoof its contents and modify all the values ​​of the data object passed to the HTML. This issue has been patched in version 7.5.2.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43865">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43864 – React Router is a router for React. Starting in version 7.2.0 and prior to versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43864</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43864</guid>
    <pubDate>Fri, 25 Apr 2025 01:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43864</strong></p>
  <p>React Router is a router for React. Starting in version 7.2.0 and prior to version 7.5.2, it is possible to force an application to switch to SPA mode by adding a header to the request. If the application uses SSR and is forced to switch to SPA, this causes an error that completely corrupts the page. If a cache system is in place, this allows the response containing the error to be cached, result…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43864">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31137 – React Router is a multi-strategy router for React bridging the gap from React 18...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31137</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31137</guid>
    <pubDate>Tue, 01 Apr 2025 19:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31137</strong></p>
  <p>React Router is a multi-strategy router for React bridging the gap from React 18 to React 19. There is a vulnerability in Remix/React Router that affects all Remix 2 and React Router 7 consumers using the Express adapter. Basically, this vulnerability allows anyone to spoof the URL used in an incoming Request by putting a URL pathname in the port section of a URL that is part of a Host or X-Forwa…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31137">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-29927 – Next.js is a React framework for building full-stack web applications. Starting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29927</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29927</guid>
    <pubDate>Fri, 21 Mar 2025 15:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-29927</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain th…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29927">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-25187 – Joplin is a free, open source note taking and to-do application, which can handl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25187</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25187</guid>
    <pubDate>Fri, 07 Feb 2025 23:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-25187</strong></p>
  <p>Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by adding note titles to the document using React's `dangerouslySetInnerHTML`, without first escaping HTML entities. Joplin lacks a Content-Security-Policy with a restrictive `script-src`. This allows arbitrary JavaScript execution via in…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25187">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-51479 – Next.js is a React framework for building full-stack web applications. In affect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51479</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51479</guid>
    <pubDate>Tue, 17 Dec 2024 19:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-51479</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed for pages directly under the application's root directory. For example: * [Not affected] `https://example.com/` * [Affected] `https://example.com/foo` * [Not affected]…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51479">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52004 – MediaCMS is an open source video and media CMS, written in Python/Django and Rea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52004</guid>
    <pubDate>Fri, 08 Nov 2024 23:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52004</strong></p>
  <p>MediaCMS is an open source video and media CMS, written in Python/Django and React, featuring a REST API. MediaCMS has been prone to vulnerabilities that upon special cases can lead to remote code execution. All versions before v4.1.0 are susceptible, and users are highly recommended to upgrade. The vulnerabilities are related with insufficient input validation while uploading media content. The…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47824 – matrix-react-sdk is react-based software development kit for inserting a Matrix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47824</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47824</guid>
    <pubDate>Tue, 15 Oct 2024 16:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47824</strong></p>
  <p>matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starting in version 3.18.0 and before 3.102.0, matrix-react-sdk allows a malicious homeserver to potentially steal message keys for a room when a user invites another user to that room, via injection of a malicious device controlled by the homeserver. This is possible because matrix-r…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47824">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47779 – Element is a Matrix web client built using the Matrix React SDK. Element Web ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47779</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47779</guid>
    <pubDate>Tue, 15 Oct 2024 16:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47779</strong></p>
  <p>Element is a Matrix web client built using the Matrix React SDK. Element Web versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access token becoming exposed to third parties. At least one vector has been identified internally, involving malicious widgets, but other vectors may exist. Note that despite superficial similarity to CVE-…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47779">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-46982 – Next.js is a React framework for building full-stack web applications. By sendin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46982</guid>
    <pubDate>Tue, 17 Sep 2024 22:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-46982</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered route in the pages router (this does not affect the app router). When this crafted request is sent it could coerce Next.js to cache a route that is meant to not be cached and send a `Cache-Control: s-maxage=1, stale-whil…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-42347 – matrix-react-sdk  is a react-based SDK for inserting a Matrix chat/voip client i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42347</guid>
    <pubDate>Tue, 06 Aug 2024 18:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-42347</strong></p>
  <p>matrix-react-sdk  is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server. This was patched in matrix-react-sdk 3.105.0. Deployments that trust their homeservers, as we…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-359</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-40631 – Plate media is an open source, rich-text editor for React. Editors that use `Med...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40631</guid>
    <pubDate>Mon, 15 Jul 2024 19:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-40631</strong></p>
  <p>Plate media is an open source, rich-text editor for React. Editors that use `MediaEmbedElement` and pass custom `urlParsers` to the `useMediaState` hook may be vulnerable to XSS if a custom parser allows `javascript:`, `data:` or `vbscript:` URLs to be embedded. Editors that do not use `urlParsers` and consume the `url` property directly may also be vulnerable if the URL is not sanitised. The def…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39903 – Solara is a pure Python, React-style framework for scaling Jupyter and web apps...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39903</guid>
    <pubDate>Fri, 12 Jul 2024 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39903</strong></p>
  <p>Solara is a pure Python, React-style framework for scaling Jupyter and web apps. A Local File Inclusion (LFI) vulnerability was identified in widgetti/solara, in version <1.35.1, which was fixed in version 1.35.1. This vulnerability arises from the application's failure to properly validate URI fragments for directory traversal sequences such as '../' when serving static files. An attacker can ex…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39693 – Next.js is a React framework. A Denial of Service (DoS) condition was identified...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39693</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39693</guid>
    <pubDate>Wed, 10 Jul 2024 20:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39693</strong></p>
  <p>Next.js is a React framework. A Denial of Service (DoS) condition was identified in Next.js. Exploitation of the bug can trigger a crash, affecting the availability of the server. his vulnerability was resolved in Next.js 13.5 and later.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39693">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-34351 – Next.js is a React framework that can provide building blocks to create web appl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34351</guid>
    <pubDate>Tue, 14 May 2024 15:38:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-34351</strong></p>
  <p>Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the `Host` header is modified, and the below conditions are also met, an attacker may be able to make requests that appear to be originating from the Next.js application server itself. The required conditions are…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-34350 – Next.js is a React framework that can provide building blocks to create web appl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34350</guid>
    <pubDate>Tue, 14 May 2024 15:38:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-34350</strong></p>
  <p>Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafted HTTP request meant that requests are treated as both a single request, and two separate requests by Next.js, leading to desynchronized responses. This led to a response queue poisoning vulnerability in the affected Next.js versions. For a request t…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-34342 – react-pdf displays PDFs in React apps. If PDF.js is used to load a malicious PDF...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34342</guid>
    <pubDate>Tue, 07 May 2024 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-34342</strong></p>
  <p>react-pdf displays PDFs in React apps. If PDF.js is used to load a malicious PDF, and PDF.js is configured with `isEvalSupported` set to `true` (which is the default value), unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain. This vulnerability is fixed in 7.7.3 and 8.0.2.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34342">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-25466 – Directory Traversal vulnerability in React Native Document Picker before v.9.1.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25466</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25466</guid>
    <pubDate>Fri, 16 Feb 2024 09:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-25466</strong></p>
  <p>Directory Traversal vulnerability in React Native Document Picker before v.9.1.1 and fixed in v.9.1.1 allows a local attacker to execute arbitrary code via a crafted script to the Android library component.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-26</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25466">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22107 – An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method syst...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22107</guid>
    <pubDate>Fri, 02 Feb 2024 16:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22107</strong></p>
  <p>An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React/SystemSettingsController.php is vulnerable to command injection via the /old/react/v1/api/system/dns/data endpoint. An authenticated attacker can abuse it to inject an arbitrary command and compromise the platform.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24558 – TanStack Query supplies asynchronous state management, server-state utilities an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24558</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24558</guid>
    <pubDate>Tue, 30 Jan 2024 20:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24558</strong></p>
  <p>TanStack Query supplies asynchronous state management, server-state utilities and data fetching for the web.  The `@tanstack/react-query-next-experimental` NPM package is vulnerable to a cross-site scripting vulnerability. To exploit this, an attacker would need to either inject malicious input or arrange to have malicious input be returned from an endpoint. To fix this issue, please update to ve…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24558">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-51843 – react-dashboard 1.4.0 is vulnerable to Cross Site Scripting (XSS) as httpOnly is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-51843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-51843</guid>
    <pubDate>Tue, 30 Jan 2024 01:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-51843</strong></p>
  <p>react-dashboard 1.4.0 is vulnerable to Cross Site Scripting (XSS) as httpOnly is not set.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-51843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-34245 – @udecode/plate-link is the link handler for the udecode/plate rich-text editor p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34245</guid>
    <pubDate>Fri, 09 Jun 2023 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-34245</strong></p>
  <p>@udecode/plate-link is the link handler for the udecode/plate rich-text editor plugin system for Slate & React. Affected versions of the link plugin and link UI component do not sanitize URLs to prevent use of the `javascript:` scheme. As a result, links with JavaScript URLs can be inserted into the Plate editor through various means, including opening or pasting malicious content. `@udecode/plat…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-30470 – A use-after-free related to unsound inference in the bytecode generation when op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30470</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30470</guid>
    <pubDate>Thu, 18 May 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-30470</strong></p>
  <p>A use-after-free related to unsound inference in the bytecode generation when optimizations are enabled for Hermes prior to commit da8990f737ebb9d9810633502f65ed462b819c09 could have been used by an attacker to achieve remote code execution. Note that this is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30470">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-28081 – A bytecode optimization bug in Hermes prior to commit e6ed9c1a4b02dc219de1648f44...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28081</guid>
    <pubDate>Thu, 18 May 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-28081</strong></p>
  <p>A bytecode optimization bug in Hermes prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could be used to cause an use-after-free and obtain arbitrary code execution via a carefully crafted payload. Note that this is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-25933 – A type confusion bug in TypedArray prior to commit e6ed9c1a4b02dc219de1648f44cd8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25933</guid>
    <pubDate>Thu, 18 May 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-25933</strong></p>
  <p>A type confusion bug in TypedArray prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could have been used by a malicious attacker to execute arbitrary code via untrusted JavaScript. Note that this is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-24833 – A use-after-free in BigIntPrimitive addition in Hermes prior to commit a6dcafe6d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24833</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24833</guid>
    <pubDate>Thu, 18 May 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-24833</strong></p>
  <p>A use-after-free in BigIntPrimitive addition in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by an attacker to leak raw data from Hermes VM’s heap. Note that this is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24833">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-24832 – A null pointer dereference bug in Hermes prior to commit 5cae9f72975cf0e5a62b27f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24832</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24832</guid>
    <pubDate>Thu, 18 May 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-24832</strong></p>
  <p>A null pointer dereference bug in Hermes prior to commit 5cae9f72975cf0e5a62b27fdd8b01f103e198708 could have been used by an attacker to crash an Hermes runtime where the EnableHermesInternal config option was set to true. Note that this is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24832">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-23557 – An error in Hermes' algorithm for copying objects properties prior to commit a00...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23557</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23557</guid>
    <pubDate>Thu, 18 May 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-23557</strong></p>
  <p>An error in Hermes' algorithm for copying objects properties prior to commit a00d237346894c6067a594983be6634f4168c9ad could be used by a malicious attacker to execute arbitrary code via type confusion. Note that this is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23557">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-23556 – An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23556</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23556</guid>
    <pubDate>Thu, 18 May 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-23556</strong></p>
  <p>An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by a malicious attacker to execute arbitrary code due to an out-of-bound write. Note that this bug is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23556">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-28103 – matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. In certain ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-28103</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-28103</guid>
    <pubDate>Tue, 28 Mar 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-28103</strong></p>
  <p>matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. In certain configurations, data sent by remote servers containing special strings in key locations could cause modifications of the `Object.prototype`, disrupting matrix-react-sdk functionality, causing denial of service and potentially affecting program logic. This is fixed in matrix-react-sdk 3.69.0 and users are advised to up…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-28103">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-36060 – matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. Events sent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36060</guid>
    <pubDate>Tue, 28 Mar 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-36060</strong></p>
  <p>matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. Events sent with special strings in key places can temporarily disrupt or impede the matrix-react-sdk from functioning properly, such as by causing room or event tile crashes. The remainder of the application can appear functional, though certain rooms/events will not be rendered. This issue has been fixed in matrix-react-sdk 3.…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22491 – Gatsby is a free and open source framework based on React that helps developers ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22491</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22491</guid>
    <pubDate>Fri, 13 Jan 2023 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22491</strong></p>
  <p>Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-transformer-remark plugin prior to versions 5.25.1 and 6.3.2 passes input through to the `gray-matter` npm package, which is vulnerable to JavaScript injection in its default configuration, unless input is sanitized.  The vulnerability is present in gatsby-transformer-remark when pa…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22491">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-39382 – Keystone is a headless CMS for Node.js — built with GraphQL and React.`@keystone...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39382</guid>
    <pubDate>Thu, 03 Nov 2022 14:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-39382</strong></p>
  <p>Keystone is a headless CMS for Node.js — built with GraphQL and React.`@keystone-6/core@3.0.0 || 3.0.1` users that use `NODE_ENV` to trigger security-sensitive functionality in their production builds are vulnerable to `NODE_ENV` being inlined to `"development"` for user code, irrespective of what your environment variables. If you do not use `NODE_ENV` in your user code to trigger security-sensi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-40138 – An integer conversion error in Hermes bytecode generation, prior to commit 6aa82...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40138</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40138</guid>
    <pubDate>Tue, 11 Oct 2022 02:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-40138</strong></p>
  <p>An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, could have been used to perform Out-Of-Bounds operations and subsequently execute arbitrary code. Note that this is only exploitable in cases where Hermes is used to execute untrusted JavaScript. Hence, most React Native applications are not affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-681</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40138">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-35289 – A write-what-where condition in hermes caused by an integer overflow, prior to c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35289</guid>
    <pubDate>Tue, 11 Oct 2022 02:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-35289</strong></p>
  <p>A write-what-where condition in hermes caused by an integer overflow, prior to commit 5b6255ae049fa4641791e47fad994e8e8c4da374 allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-680</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-32234 – An out of bounds write in hermes, while handling large arrays, prior to commit 0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32234</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32234</guid>
    <pubDate>Tue, 11 Oct 2022 01:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-32234</strong></p>
  <p>An out of bounds write in hermes, while handling large arrays, prior to commit 06eaec767e376bfdb883d912cb15e987ddf2bda1 allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32234">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-36010 – This library allows strings to be parsed as functions and stored as a specialize...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36010</guid>
    <pubDate>Mon, 15 Aug 2022 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-36010</strong></p>
  <p>This library allows strings to be parsed as functions and stored as a specialized component, [`JsonFunctionValue`](https://github.com/oxyno-zeta/react-editable-json-tree/blob/09a0ca97835b0834ad054563e2fddc6f22bc5d8c/src/components/JsonFunctionValue.js). To do this, Javascript's [`eval`](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval) function is used to exec…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-95</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31103 – lettersanitizer is a DOM-based HTML email sanitizer for in-browser email renderi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31103</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31103</guid>
    <pubDate>Mon, 27 Jun 2022 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31103</strong></p>
  <p>lettersanitizer is a DOM-based HTML email sanitizer for in-browser email rendering. All versions of lettersanitizer below 1.0.2 are affected by a denial of service issue when processing a CSS at-rule `@keyframes`. This package is depended on by [react-letter](https://github.com/mat-sz/react-letter), therefore everyone using react-letter is also at risk. The problem has been patched in version 1.0…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31103">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-25863 – The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-25863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-25863</guid>
    <pubDate>Fri, 10 Jun 2022 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-25863</strong></p>
  <p>The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted Data when passing input through to the gray-matter package, due to its default configurations that are missing input sanitization. Exploiting this vulnerability is possible when passing input in both webpack (MDX files in src/pages or MDX file imported as a component in fronten…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-25863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24709 – @awsui/components-react is the main AWS UI package which contains React componen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24709</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24709</guid>
    <pubDate>Thu, 24 Feb 2022 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24709</strong></p>
  <p>@awsui/components-react is the main AWS UI package which contains React components, with TypeScript definitions designed for user interface development. Multiple components in versions before 3.0.367 have been found to not properly neutralize user input and may allow for javascript injection. Users are advised to upgrade to version 3.0.367 or later. There are no known workarounds for this issue.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24709">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-24045 – A type confusion vulnerability could be triggered when resolving the "typeof" un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-24045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-24045</guid>
    <pubDate>Mon, 13 Dec 2021 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-24045</strong></p>
  <p>A type confusion vulnerability could be triggered when resolving the "typeof" unary operator in Facebook Hermes prior to v0.10.0. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-24045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43803 – Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43803</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43803</guid>
    <pubDate>Fri, 10 Dec 2021 00:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43803</strong></p>
  <p>Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to a server crash. In order to be affected by this issue, the deployment must use Next.js versions above 11.1.0 and below 12.0.5, Node.js above 15.0.0, and next start or a custom server. Deployments on Vercel are not affected, along with similar environments where invalid requests…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43803">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41249 – GraphQL Playground is a GraphQL IDE for development of graphQL focused applicati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41249</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41249</guid>
    <pubDate>Thu, 04 Nov 2021 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41249</strong></p>
  <p>GraphQL Playground is a GraphQL IDE for development of graphQL focused applications. All versions of graphql-playground-react older than graphql-playground-react@1.7.28 are vulnerable to compromised HTTP schema introspection responses or schema prop values with malicious GraphQL type names, exposing a dynamic XSS attack surface that can allow code injection on operation autocomplete. In order for…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41249">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41129 – Pterodactyl is an open-source game server management panel built with PHP 7, Rea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41129</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41129</guid>
    <pubDate>Wed, 06 Oct 2021 20:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41129</strong></p>
  <p>Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmation_token` input during the two-factor authentication process to reference a cache value not associated with the login attempt. In rare cases this can allow a malicious actor to authenticate as a random user in the Panel. The malicious user must targe…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41129">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39178 – Next.js is a React framework. Versions of Next.js between 10.0.0 and 11.0.0 cont...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39178</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39178</guid>
    <pubDate>Tue, 31 Aug 2021 00:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39178</strong></p>
  <p>Next.js is a React framework. Versions of Next.js between 10.0.0 and 11.0.0 contain a cross-site scripting vulnerability. In order for an instance to be affected by the vulnerability, the `next.config.js` file must have `images.domains` array assigned and the image host assigned in `images.domains` must allow user-provided SVG. If the `next.config.js` file has `images.loader` assigned to somethin…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39178">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-24037 – A use after free in hermes, while emitting certain error messages, prior to comm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-24037</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-24037</guid>
    <pubDate>Tue, 15 Jun 2021 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-24037</strong></p>
  <p>A use after free in hermes, while emitting certain error messages, prior to commit d86e185e485b6330216dee8e854455c694e3a36e allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-24037">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-1920 – A regular expression denial of service (ReDoS) vulnerability in the validateBase...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1920</guid>
    <pubDate>Tue, 01 Jun 2021 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-1920</strong></p>
  <p>A regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive resources, become unresponsive, or crash. This was introduced in react-native version 0.59.0 and fixed in version 0.64.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1333</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-1896 – A stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1896</guid>
    <pubDate>Tue, 02 Feb 2021 07:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-1896</strong></p>
  <p>A stack overflow vulnerability in Facebook Hermes 'builtin apply' prior to commit 86543ac47e59c522976b5632b8bf9a2a4583c7d2 (https://github.com/facebook/hermes/commit/86543ac47e59c522976b5632b8bf9a2a4583c7d2) allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. H…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7787 – This affects all versions of package react-adal. It is possible for a specially ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7787</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7787</guid>
    <pubDate>Wed, 09 Dec 2020 17:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7787</strong></p>
  <p>This affects all versions of package react-adal. It is possible for a specially crafted JWT token and request URL can cause the nonce, session and refresh values to be incorrectly validated, causing the application to treat an attacker-generated JWT token as authentic. The logical defect is caused by how the nonce, session and refresh values are stored in the browser local storage or session stor…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7787">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-1915 – An out-of-bounds read in the JavaScript Interpreter in Facebook Hermes prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1915</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1915</guid>
    <pubDate>Mon, 26 Oct 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-1915</strong></p>
  <p>An out-of-bounds read in the JavaScript Interpreter in Facebook Hermes prior to commit 8cb935cd3b2321c46aa6b7ed8454d95c75a7fca0 allows attackers to cause a denial of service attack or possible further memory corruption via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1915">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-1914 – A logic vulnerability when handling the SaveGeneratorLong instruction in Faceboo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1914</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1914</guid>
    <pubDate>Thu, 08 Oct 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-1914</strong></p>
  <p>A logic vulnerability when handling the SaveGeneratorLong instruction in Facebook Hermes prior to commit b2021df620824627f5a8c96615edbd1eb7fdddfc allows attackers to potentially read out of bounds or theoretically execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native ap…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-670</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1914">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-1913 – An Integer signedness error in the JavaScript Interpreter in Facebook Hermes pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1913</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1913</guid>
    <pubDate>Wed, 09 Sep 2020 19:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-1913</strong></p>
  <p>An Integer signedness error in the JavaScript Interpreter in Facebook Hermes prior to commit 2c7af7ec481ceffd0d14ce2d7c045e475fd71dc6 allows attackers to cause a denial of service attack or a potential RCE via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-195</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1913">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-1912 – An out-of-bounds read/write vulnerability when executing lazily compiled inner g...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1912</guid>
    <pubDate>Wed, 09 Sep 2020 19:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-1912</strong></p>
  <p>An out-of-bounds read/write vulnerability when executing lazily compiled inner generator functions in Facebook Hermes prior to commit 091835377369c8fd5917d9b87acffa721ad2a168 allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applicati…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1912">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-1911 – A type confusion vulnerability when resolving properties of JavaScript objects w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1911</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1911</guid>
    <pubDate>Fri, 04 Sep 2020 03:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-1911</strong></p>
  <p>A type confusion vulnerability when resolving properties of JavaScript objects with specially-crafted prototype chains in Facebook Hermes prior to commit fe52854cdf6725c2eaa9e125995da76e6ceb27da allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most Re…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-843</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1911">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-12164 – ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12164</guid>
    <pubDate>Tue, 23 Jul 2019 23:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-12164</strong></p>
  <p>ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows Remote Code Execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-6342 – react-dev-utils on Windows allows developers to run a local webserver for accept...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6342</guid>
    <pubDate>Mon, 31 Dec 2018 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-6342</strong></p>
  <p>react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an editor. The input to that command was not properly sanitized, allowing an attacker who can make a network request to the server (either via CSRF or by direct request) to execute arbitrary commands on the targeted system. This issue affects multiple branches: 1.x.x…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6342">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10697 – react-native-baidu-voice-synthesizer is a baidu voice speech synthesizer for rea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10697</guid>
    <pubDate>Mon, 04 Jun 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10697</strong></p>
  <p>react-native-baidu-voice-synthesizer is a baidu voice speech synthesizer for react native. react-native-baidu-voice-synthesizer downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-7920 – An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7920</guid>
    <pubDate>Mon, 07 Aug 2017 08:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-7920</strong></p>
  <p>An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access internal information about status and connected devices without authenticating.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7920">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
