<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – React</title>
  <link>https://cvedaily.com/pages/tags/react.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/react.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – React</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:32 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-42342 – React Router is a router for React. In versions 7.0.0 through 7.14.x of react-ro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42342</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42342</strong></p>
  <p>React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can consume disproportionate server resources via unbounded path expansion in the __manifest endpoint, resulting in response time degradation and/or service unavailability for end users. This affects React Router Framework M…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42342">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42211 – React Router is a router for React. In versions 7.0.0 through 7.14.1, when using...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42211</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42211</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42211</strong></p>
  <p>React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unauthorized remote code execution (RCE) through external requests. This attack requires the application code to have an existing prototype pollution vulnerability, which can then be leveraged in a 2-step attack where the second step triggers unauthorized…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42211">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40181 – React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40181</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40181</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40181</strong></p>
  <p>React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigger an open redirect to an external domain due to path values starting with // being reinterpreted as protocol-relative URLs. The level of impact depends on the validation done by the application prior to returning the redirect. This does not impact a…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40181">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34077 – React Router is a router for React. In versions 7.7.0 through 7.13.1, when using...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34077</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34077</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34077</strong></p>
  <p>React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in ve…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34077">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33245 – React Router is a router for React. In versions 7.7.0 through 7.13.1, when using...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33245</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33245</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33245</strong></p>
  <p>React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in ve…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33245">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33244 – React Router is a router for React. In versions 7.5.1 through 7.13.1, when using...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33244</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33244</strong></p>
  <p>React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` header value can permit Cross-Site Scripting (XSS) in the statically generated HTML files if the redirect location comes from an untrusted source. This does not impact applications using Declarative Mode (`<BrowserRouter>`) or D…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7459 – The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPres...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7459</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7459</guid>
    <pubDate>Sat, 30 May 2026 10:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7459</strong></p>
  <p>The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subscriber+) account takeover in all versions up to, and including, 5.26.0 via the event reaction endpoints (react_to_event() / unreact_to_event()). The endpoints register get_items_permissions_check() as their permission_callback, which only verifies the requester is logged in and do…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7459">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44483 – RVF (formerly Remix Validated Form) provides easy form validation and state mana...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44483</guid>
    <pubDate>Wed, 27 May 2026 17:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44483</strong></p>
  <p>RVF (formerly Remix Validated Form) provides easy form validation and state management for React. From 6.0.0 to before 6.0.4 and 7.0.2, setPath in @rvf/set-get (used by @rvf/core to flatten incoming form data into a nested object) does not block the keys __proto__, constructor, or prototype when walking a path. Because field names in submitted form data are passed directly to setPath via preproce…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9349 – A vulnerability was determined in calcom cal.diy up to 4.9.4. Affected by this i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9349</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9349</guid>
    <pubDate>Sun, 24 May 2026 04:16:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9349</strong></p>
  <p>A vulnerability was determined in calcom cal.diy up to 4.9.4. Affected by this issue is the function getServerSideProps of the file apps/web/modules/bookings/views/bookings-single-view.getServerSideProps.tsx of the component Generic React API. This manipulation of the argument cancelledBy/rescheduledBy causes information disclosure. The attack can be initiated remotely. The exploit has been publi…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9349">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-30691 – Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30691</guid>
    <pubDate>Wed, 20 May 2026 18:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-30691</strong></p>
  <p>Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitrary JavaScript via a crafted .txt file. The TXTRenderer component fails to sanitize file content and explicitly casts raw data as a ReactNode</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44501 – DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub front...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44501</guid>
    <pubDate>Thu, 14 May 2026 16:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44501</strong></p>
  <p>DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTTP cookie during the OIDC callback flow, with no integrity protection (no HMAC, no encryption). This is a Deserialization of Untrusted Data vulnerability (CWE-502) affecting the GET /callback/oidc endpoint. Successful ex…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45109 – Next.js is a React framework for building full-stack web applications. From 15.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45109</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45109</guid>
    <pubDate>Wed, 13 May 2026 18:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45109</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed in 15.5.18 and 16.2.6.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45109">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-44582 – Next.js is a React framework for building full-stack web applications. From 13.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44582</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44582</guid>
    <pubDate>Wed, 13 May 2026 18:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-44582</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React Server Component responses can be vulnerable to cache poisoning in deployments that rely on shared caches with insufficient response partitioning. In affected conditions, collisions in the _rsc cache-busting value can allow an attacker to poison cache entries so users receive the…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-328</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44582">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44581 – Next.js is a React framework for building full-stack web applications. From 13.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44581</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44581</guid>
    <pubDate>Wed, 13 May 2026 18:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44581</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Router applications that rely on CSP nonces can be vulnerable to stored cross-site scripting when deployed behind shared caches. In affected versions, malformed nonce values derived from request headers could be reflected into rendered HTML in an unsafe way, allowing an attacker to…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44581">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44580 – Next.js is a React framework for building full-stack web applications. From 13.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44580</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44580</guid>
    <pubDate>Wed, 13 May 2026 18:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44580</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applications that use beforeInteractive scripts together with untrusted content can be vulnerable to cross-site scripting. In affected versions, serialized script content was not escaped safely before being embedded into the document, which could allow attacker-controlled input to brea…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44580">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44579 – Next.js is a React framework for building full-stack web applications. From  to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44579</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44579</guid>
    <pubDate>Wed, 13 May 2026 18:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44579</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From  to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection exhaustion through crafted POST requests to a server action. In affected configurations, a malicious request can trigger a request-body handling deadlock that leaves connections open…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44579">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44578 – Next.js is a React framework for building full-stack web applications. From 13.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44578</guid>
    <pubDate>Wed, 13 May 2026 18:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44578</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44577 – Next.js is a React framework for building full-stack web applications. From 10.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44577</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44577</guid>
    <pubDate>Wed, 13 May 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44577</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when self-hosting Next.js with the default image loader, the Image Optimization API fetches local images entirely into memory without enforcing a maximum size limit. An attacker could cause out-of-memory conditions by requesting large local assets from the /_next/image endpoint that ma…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44577">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44576 – Next.js is a React framework for building full-stack web applications. From 14.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44576</guid>
    <pubDate>Wed, 13 May 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44576</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applications using React Server Components can be vulnerable to cache poisoning when shared caches do not correctly partition response variants. Under affected conditions, an attacker can cause an RSC response to be served from the original URL and poison shared cache entries so later…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-436</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44575 – Next.js is a React framework for building full-stack web applications. From 15.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44575</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44575</guid>
    <pubDate>Wed, 13 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44575</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauthorized access through transport-specific route variants used for segment prefetching. In affected configurations, specially crafted .rsc and segment-prefetch URLs can resolve to the…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44575">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44574 – Next.js is a React framework for building full-stack web applications. From 15.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44574</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44574</guid>
    <pubDate>Wed, 13 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44574</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected c…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44574">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44573 – Next.js is a React framework for building full-stack web applications. From 12.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44573</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44573</guid>
    <pubDate>Wed, 13 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44573</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authorization can allow unauthorized access to protected page data through locale-less /_next/data/<buildId>/<page>.json requests. In affected configurations, middleware does not run for the unprefixed…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44573">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-44572 – Next.js is a React framework for building full-stack web applications. From 12.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44572</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44572</guid>
    <pubDate>Wed, 13 May 2026 16:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-44572</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path handled by middleware that returns a redirect. When that happened, the middleware/proxy could treat the request as a data request and replace the standard Location redirect header with the internal x-nex…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-349</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44572">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42192 – Plunk is an open-source email platform built on top of AWS SES. Prior to version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42192</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42192</guid>
    <pubDate>Fri, 08 May 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42192</strong></p>
  <p>Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, a stored cross-site scripting (XSS) vulnerability exists in the campaign management feature, where the email body content created by authenticated project members is stored and later rendered in the admin dashboard using React's dangerouslySetInnerHTML without any HTML sanitization. This allows a lower-privile…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42192">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42190 – RedwoodSDK is a server-first React framework. From version 1.0.0-beta.50 to befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42190</guid>
    <pubDate>Fri, 08 May 2026 20:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42190</strong></p>
  <p>RedwoodSDK is a server-first React framework. From version 1.0.0-beta.50 to before version 1.2.3, server actions in rwsdk apply HTTP method enforcement but no origin validation. A request originating from a different origin that the browser treats as same-site can invoke a server action with the victim's session cookie attached. This issue has been patched in version 1.2.3.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23870 – A denial of service vulnerability could be triggered by sending specially crafte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23870</guid>
    <pubDate>Wed, 06 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23870</strong></p>
  <p>A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.5, 19.1.0 through 19.1.6, and 19.2.0 through 19…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23870">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-41679 – Paperclip is a Node.js server and React UI that orchestrates a team of AI agents...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41679</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41679</guid>
    <pubDate>Thu, 23 Apr 2026 02:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-41679</strong></p>
  <p>Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration. No user interaction, no credentials, just the target's address. The chain consists of six API call…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41679">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41208 – Paperclip is a Node.js server and React UI that orchestrates a team of AI agents...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41208</guid>
    <pubDate>Thu, 23 Apr 2026 02:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41208</strong></p>
  <p>Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @paperclipai/server prior to 2026.416.0 contain a privilege escalation vulnerability that allows an attacker with an Agent API key to execute arbitrary OS commands on the Paperclip server host. An attacker with an agent credential can escalate privileges from the agent runtime to the Pa…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-6600 – A flaw has been found in langflow-ai langflow up to 1.8.3. This affects an unkno...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6600</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6600</guid>
    <pubDate>Mon, 20 Apr 2026 04:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-6600</strong></p>
  <p>A flaw has been found in langflow-ai langflow up to 1.8.3. This affects an unknown function of the file src/frontend/src/modals/IOModal/components/chatView/chatMessage/components/edit-message.tsx of the component Frontend React Component Rendering. Executing a manipulation can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. The ve…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6600">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40179 – Prometheus is an open-source monitoring system and time series database. Version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40179</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40179</guid>
    <pubDate>Wed, 15 Apr 2026 23:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40179</strong></p>
  <p>Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vulnerabilities in multiple components of the Prometheus web UI where metric names and label values are injected into innerHTML without escaping. In both the Mantine UI and old React UI, chart tooltips on the Graph page render metric names c…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40179">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23869 – A denial of service vulnerability exists in React Server Components, affecting t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23869</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23869</guid>
    <pubDate>Wed, 08 Apr 2026 20:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23869</strong></p>
  <p>A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered by sending specially crafted HTTP requests to Server Function endpoints.The payload of the HTTP requ…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23869">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39371 – RedwoodSDK is a server-first React framework. From 1.0.0-beta.50 to 1.0.5, erver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39371</guid>
    <pubDate>Tue, 07 Apr 2026 20:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39371</strong></p>
  <p>RedwoodSDK is a server-first React framework. From 1.0.0-beta.50 to 1.0.5, erver functions exported from "use server" files could be invoked via GET requests, bypassing their intended HTTP method. In cookie-authenticated applications, this allowed cross-site GET navigations to trigger state-changing functions, because browsers send SameSite=Lax cookies on top-level GET requests. This affected all…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-35052 – D-Tale is the combination of a Flask back-end and a React front-end to view &amp; an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35052</guid>
    <pubDate>Mon, 06 Apr 2026 18:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-35052</strong></p>
  <p>D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3.22.0, users hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. This vulnerability is fixed in 3.22.0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34456 – Reviactyl is an open-source game server management panel built using Laravel, Re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34456</guid>
    <pubDate>Wed, 01 Apr 2026 20:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34456</strong></p>
  <p>Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From version 26.2.0-beta.1 to before version 26.2.0-beta.5, a vulnerability in the OAuth authentication flow allowed automatic linking of social accounts based solely on matching email addresses. An attacker could create or control a social account (e.g., Google, GitHub, Discord) using…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-29057 – Next.js is a React framework for building full-stack web applications. Starting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29057</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29057</guid>
    <pubDate>Wed, 18 Mar 2026 01:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-29057</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. Starting in version 9.5.0 and prior to versions 15.5.13 and 16.1.7, when Next.js rewrites proxy traffic to an external backend, a crafted `DELETE`/`OPTIONS` request using `Transfer-Encoding: chunked` could trigger request boundary disagreement between the proxy and backend. This could allow request smuggling through rewritten…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29057">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27980 – Next.js is a React framework for building full-stack web applications. Starting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27980</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27980</guid>
    <pubDate>Wed, 18 Mar 2026 01:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27980</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. Starting in version 10.0.0 and prior to version 16.1.7, the default Next.js image optimization disk cache (`/_next/image`) did not have a configurable upper bound, allowing unbounded cache growth. An attacker could generate many unique image-optimization variants and exhaust disk space, causing denial of service. This is fixed…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27980">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27979 – Next.js is a React framework for building full-stack web applications. Starting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27979</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27979</guid>
    <pubDate>Wed, 18 Mar 2026 01:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27979</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, a request containing the `next-resume: 1` header (corresponding with a PPR resume request) would buffer request bodies without consistently enforcing `maxPostponedStateSize` in certain setups. The previous mitigation protected minimal-mode deployments, but equivalent non-…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27979">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27978 – Next.js is a React framework for building full-stack web applications. Starting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27978</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27978</guid>
    <pubDate>Wed, 18 Mar 2026 00:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27978</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, `origin: null` was treated as a "missing" origin during Server Action CSRF validation. As a result, requests from opaque contexts (such as sandboxed iframes) could bypass origin verification instead of being validated as cross-origin requests. An attacker could induce a v…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27978">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27977 – Next.js is a React framework for building full-stack web applications. Starting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27977</guid>
    <pubDate>Wed, 18 Mar 2026 00:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27977</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. Starting in version 16.0.1 and prior to version 16.1.7, in `next dev`, cross-site protection for internal websocket endpoints could treat `Origin: null` as a bypass case even if `allowedDevOrigins` is configured, allowing privacy-sensitive/opaque contexts (for example sandboxed documents) to connect unexpectedly. If a dev serv…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-1385</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30862 – Appsmith is a platform to build admin panels, internal tools, and dashboards. Pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30862</guid>
    <pubDate>Tue, 10 Mar 2026 17:40:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30862</strong></p>
  <p>Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.96, a Critical Stored XSS vulnerability exists in the Table Widget (TableWidgetV2). The root cause is a lack of HTML sanitization in the React component rendering pipeline, allowing malicious attributes to be interpolated into the DOM. By leveraging the "Invite Users" feature, an attacker with a regular user…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28194 – In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28194</guid>
    <pubDate>Wed, 25 Feb 2026 14:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28194</strong></p>
  <p>In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28194">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27612 – Repostat is a React component to fetch and display GitHub repository info. Prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27612</guid>
    <pubDate>Wed, 25 Feb 2026 03:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27612</strong></p>
  <p>Repostat is a React component to fetch and display GitHub repository info. Prior to version 1.0.1, the `RepoCard` component is vulnerable to Reflected Cross-Site Scripting (XSS). The vulnerability occurs because the component uses React's `dangerouslySetInnerHTML` to render the repository name (`repo` prop) during the loading state without any sanitization. If a developer using this package passe…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23864 – Multiple denial of service vulnerabilities exist in React Server Components, aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23864</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23864</guid>
    <pubDate>Mon, 26 Jan 2026 20:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23864</strong></p>
  <p>Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack.  The vulnerabilities are triggered by sending specially crafted HTTP requests to Server Function endpoints, and could lead to server crashes, out-of-memory exceptions or excessive CPU usage; depending on the v…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23864">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22030 – React Router is a router for React. In @remix-run/server-runtime version prior t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22030</guid>
    <pubDate>Sat, 10 Jan 2026 03:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22030</strong></p>
  <p>React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, React Router (or Remix v2) is vulnerable to CSRF attacks on document POST requests to UI routes when using server-side route action handlers in Framework Mode, or when using React Server Actions in the new unstable RSC modes. There is no impact if Declarative Mode (<Bro…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22029 – React Router is a router for React. In @remix-run/router version prior to 1.23.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22029</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22029</guid>
    <pubDate>Sat, 10 Jan 2026 03:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22029</strong></p>
  <p>React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if you are creating red…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22029">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21884 – React Router is a router for React. In @remix-run/react version prior to 2.17.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21884</guid>
    <pubDate>Sat, 10 Jan 2026 03:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21884</strong></p>
  <p>React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router's <ScrollRestoration> API in Framework Mode when using the getKey/storageKey props during Server-Side Rendering which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the keys. There is n…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-68470 – React Router is a router for React. In versions 6.0.0 through 6.30.1 and 7.0.0 t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68470</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68470</guid>
    <pubDate>Sat, 10 Jan 2026 03:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-68470</strong></p>
  <p>React Router is a router for React. In versions 6.0.0 through 6.30.1 and 7.0.0 through 7.9.5, an attacker-supplied path can be crafted so that when a React Router application navigates to it via navigate(), <Link>, or redirect(), the app performs a navigation/redirect to an external URL. This is only an issue if you are passing untrusted content into navigation paths in your application code. Thi…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68470">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-61686 – React Router is a router for React. In @react-router/node versions 7.0.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61686</guid>
    <pubDate>Sat, 10 Jan 2026 03:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-61686</strong></p>
  <p>React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if createFileSessionStorage() is being used from @react-router/node (or @remix-run/node/@remix-run/deno in Remix v2) with an unsigned cookie, it is possible for an attacker to cause the session to try to read/write from a loc…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59057 – React Router is a router for React. In @remix-run/react versions 1.15.0 through ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59057</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59057</guid>
    <pubDate>Sat, 10 Jan 2026 03:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59057</strong></p>
  <p>React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the tag. There is no impact if the applica…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59057">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68155 – @vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68155</guid>
    <pubDate>Tue, 16 Dec 2025 19:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68155</strong></p>
  <p>@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_findSourceMapURL` endpoint in `@vitejs/plugin-rsc` allows unauthenticated arbitrary file read during development mode. An attacker can read any file accessible to the Node.js process by sending a crafted HTTP request with a `file://` URL in the `filename` query parameter. Version 0.…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67779 – It was found that the fix addressing CVE-2025-55184 in React Server Components w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67779</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67779</guid>
    <pubDate>Fri, 12 Dec 2025 00:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67779</strong></p>
  <p>It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Components versions 19.0.2, 19.1.3 and 19.2.2 are affected, allowing unsafe deserialization of payloads from HTTP requests to Server Function endpoints. This can cause an infinite loop that hangs the server process and may p…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67779">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55184 – A pre-authentication denial of service vulnerability exists in React Server Comp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55184</guid>
    <pubDate>Thu, 11 Dec 2025 20:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55184</strong></p>
  <p>A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints, which can cause an infinite…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-55183 – An information leak vulnerability exists in specific configurations of React Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55183</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55183</guid>
    <pubDate>Thu, 11 Dec 2025 20:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-55183</strong></p>
  <p>An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. A specifically crafted HTTP request sent to a vulnerable Server Function may unsafely return the source code of any Serv…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55183">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-67489 – @vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67489</guid>
    <pubDate>Tue, 09 Dec 2025 21:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-67489</strong></p>
  <p>@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versions 0.5.5 and below are vulnerable to arbitrary remote code execution on the development server through unsafe dynamic imports in server function APIs (loadServerAction, decodeReply, decodeAction) when integrated into RSC applications that expose server function endpoints. Attackers with network access to the developm…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-55182 – A pre-authentication remote code execution vulnerability exists in React Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55182</guid>
    <pubDate>Wed, 03 Dec 2025 16:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-55182</strong></p>
  <p>A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-11953 – The Metro Development Server, which is opened by the React Native Community CLI,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11953</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11953</guid>
    <pubDate>Mon, 03 Nov 2025 17:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-11953</strong></p>
  <p>The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlle…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11953">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-59161 – Element Web is a Matrix web client built using the Matrix React SDK. Element Web...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59161</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59161</guid>
    <pubDate>Tue, 16 Sep 2025 17:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-59161</strong></p>
  <p>Element Web is a Matrix web client built using the Matrix React SDK. Element Web and Element Desktop before version 1.11.112 have insufficient validation of room predecessor links, allowing a remote attacker to attempt to impermanently replace a room's entry in the room list with an unrelated attacker-supplied room. While the effect of this is temporary, it may still confuse users into acting on…</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59161">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-57822 – Next.js is a React framework for building full-stack web applications. Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57822</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57822</guid>
    <pubDate>Fri, 29 Aug 2025 22:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-57822</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly passing the request object, it could lead to SSRF in self-hosted applications that incorrectly forwarded user-supplied headers. This vulnerability has been fixed in Next.js versions 14.2.32 and 15.4.7. All users implementing custom middleware logic i…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57822">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-57752 – Next.js is a React framework for building full-stack web applications. In versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57752</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57752</guid>
    <pubDate>Fri, 29 Aug 2025 22:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-57752</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to before 15.4.5, Next.js Image Optimization API routes are affected by cache key confusion. When images returned from API routes vary based on request headers (such as Cookie or Authorization), these responses could be incorrectly cached and served to unauthorized users due to a cach…</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-524</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57752">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-55173 – Next.js is a React framework for building full-stack web applications. In versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55173</guid>
    <pubDate>Fri, 29 Aug 2025 22:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-55173</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to before 15.4.5, Next.js Image Optimization is vulnerable to content injection. The issue allowed attacker-controlled external image sources to trigger file downloads with arbitrary content and filenames under specific configurations. This behavior could be abused for phishing or mal…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58047 – Volto is a React based frontend for the Plone Content Management System. In vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58047</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58047</guid>
    <pubDate>Thu, 28 Aug 2025 18:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58047</strong></p>
  <p>Volto is a React based frontend for the Plone Content Management System. In versions from 19.0.0-alpha.1 to before 19.0.0-alpha.4, 18.0.0 to before 18.24.0, 17.0.0 to before 17.22.1, and prior to 16.34.0, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL. The problem has been patched in versions 16.34.0, 17.22.1, 18.24.0, and 19.0.0-a…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58047">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-55008 – The AuthKit library for React Router 7+ provides helpers for authentication and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-55008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-55008</guid>
    <pubDate>Sat, 09 Aug 2025 03:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-55008</strong></p>
  <p>The AuthKit library for React Router 7+ provides helpers for authentication and session management using WorkOS & AuthKit with React Router. In versions 0.6.1 and below, @workos-inc/authkit-react-router exposed sensitive authentication artifacts — specifically sealedSession and accessToken by returning them from the authkitLoader. This caused them to be rendered into the browser HTML. This issue…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54594 – react-native-bottom-tabs is a library of Native Bottom Tabs for React Native. In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54594</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54594</guid>
    <pubDate>Wed, 06 Aug 2025 00:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54594</strong></p>
  <p>react-native-bottom-tabs is a library of Native Bottom Tabs for React Native. In versions 0.9.2 and below, the github/workflows/release-canary.yml GitHub Actions repository workflow improperly used the pull_request_target event trigger, which allowed for untrusted code from a forked pull request to be executed in a privileged context. An attacker could create a pull request containing a malicious…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54594">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-52078 – File upload vulnerability in Writebot AI Content Generator SaaS React Template t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52078</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52078</guid>
    <pubDate>Tue, 05 Aug 2025 20:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-52078</strong></p>
  <p>File upload vulnerability in Writebot AI Content Generator SaaS React Template thru 4.0.0, allowing remote attackers to gain escalated privileges via a crafted POST request to the /file-upload endpoint.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52078">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-36850 – An information disclosure vulnerability exits in Sitecore JSS React Sample Appli...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36850</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36850</guid>
    <pubDate>Fri, 25 Jul 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-36850</strong></p>
  <p>An information disclosure vulnerability exits in Sitecore JSS React Sample Application 11.0.0 - 14.0.1 that may cause page content intended for one user to be shown to another user.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36850">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53626 – pdfme is a TypeScript-based PDF generator and React-based UI. The expression eva...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53626</guid>
    <pubDate>Thu, 10 Jul 2025 19:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53626</strong></p>
  <p>pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabilities allowing sandbox escape leading to XSS and prototype pollution attacks. This vulnerability is fixed in 5.4.1.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49826 – Next.js is a React framework for building full-stack web applications. From vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49826</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49826</guid>
    <pubDate>Thu, 03 Jul 2025 21:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49826</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. From versions 15.0.4-canary.51 to before 15.1.8, a cache poisoning bug leading to a Denial of Service (DoS) condition was found in Next.js. This issue does not impact customers hosted on Vercel. Under certain conditions, this issue may allow a HTTP 204 response to be cached for static pages, leading to the 204 response being s…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49826">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-49005 – Next.js is a React framework for building full-stack web applications. In Next.j...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49005</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49005</guid>
    <pubDate>Thu, 03 Jul 2025 21:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-49005</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. In Next.js App Router from 15.3.0 to before 15.3.3 and Vercel CLI from 41.4.1 to 42.2.0, a cache poisoning vulnerability was found. The issue allowed page requests for HTML content to return a React Server Component (RSC) payload instead under certain conditions. When deployed to Vercel, this would only impact the browser cach…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49005">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-5896 – A vulnerability was found in tarojs taro up to 4.1.1. It has been declared as pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5896</guid>
    <pubDate>Mon, 09 Jun 2025 21:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-5896</strong></p>
  <p>A vulnerability was found in tarojs taro up to 4.1.1. It has been declared as problematic. This vulnerability affects unknown code of the file taro/packages/css-to-react-native/src/index.js. The manipulation leads to inefficient regular expression complexity. The attack can be initiated remotely. Upgrading to version 4.1.2 is able to address this issue. The name of the patch is c2e321a8b6fc873427…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-45001 – react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-45001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-45001</guid>
    <pubDate>Mon, 09 Jun 2025 17:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-45001</strong></p>
  <p>react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaintext in the compiled native binary. Attackers can extract these secrets using basic static analysis tools.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-45001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49006 – Wasp (Web Application Specification) is a Rails-like framework for React, Node.j...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49006</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49006</guid>
    <pubDate>Mon, 09 Jun 2025 13:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49006</strong></p>
  <p>Wasp (Web Application Specification) is a Rails-like framework for React, Node.js, and Prisma. Prior to version 0.16.6, Wasp authentication has a vulnerability in the OAuth authentication implementation (affecting only Keycloak with a specific config). Wasp currently lowercases OAuth user IDs before storing / fetching them. This behavior violates OAuth and OpenID Connect specifications and can re…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49006">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-48068 – Next.js is a React framework for building full-stack web applications. In versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48068</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48068</guid>
    <pubDate>Fri, 30 May 2025 04:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-48068</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. In versions starting from 13.0 to before 14.2.30 and 15.0.0 to before 15.2.2, Next.js may have allowed limited source code exposure when the dev server was running with the App Router enabled. The vulnerability only affects local development environments and requires the user to visit a malicious webpage while npm run dev is a…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1385</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48068">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-32421 – Next.js is a React framework for building full-stack web applications. Versions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32421</guid>
    <pubDate>Wed, 14 May 2025 23:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-32421</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. Versions prior to 14.2.24 and 15.1.6 have a race-condition vulnerability. This issue only affects the Pages Router under certain misconfigurations, causing normal endpoints to serve `pageProps` data instead of standard HTML. This issue was patched in versions 15.1.6 and 14.2.24 by stripping the `x-now-route-matches` header fro…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43865 – React Router is a router for React. In versions on the 7.0 branch prior to versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43865</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43865</guid>
    <pubDate>Fri, 25 Apr 2025 01:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43865</strong></p>
  <p>React Router is a router for React. In versions on the 7.0 branch prior to version 7.5.2, it's possible to modify pre-rendered data by adding a header to the request. This allows to completely spoof its contents and modify all the values ​​of the data object passed to the HTML. This issue has been patched in version 7.5.2.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43865">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-43864 – React Router is a router for React. Starting in version 7.2.0 and prior to versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43864</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43864</guid>
    <pubDate>Fri, 25 Apr 2025 01:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-43864</strong></p>
  <p>React Router is a router for React. Starting in version 7.2.0 and prior to version 7.5.2, it is possible to force an application to switch to SPA mode by adding a header to the request. If the application uses SSR and is forced to switch to SPA, this causes an error that completely corrupts the page. If a cache system is in place, this allows the response containing the error to be cached, result…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43864">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-32026 – Element Web is a Matrix web client built using the Matrix React SDK. Element Web...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32026</guid>
    <pubDate>Tue, 08 Apr 2025 16:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-32026</strong></p>
  <p>Element Web is a Matrix web client built using the Matrix React SDK. Element Web, starting from version 1.11.16 up to version 1.11.96, can be configured to load Element Call from an external URL. Under certain conditions, the external page is able to get access to the media encryption keys used for an Element Call call. Version 1.11.97 fixes the problem.</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-3191 – All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3191</guid>
    <pubDate>Fri, 04 Apr 2025 05:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-3191</strong></p>
  <p>All versions of the package react-draft-wysiwyg are vulnerable to Cross-site Scripting (XSS) via the Embedded button which will then result in saving the payload in the <iframe> tag.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30218 – Next.js is a React framework for building full-stack web applications. To mitiga...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30218</guid>
    <pubDate>Wed, 02 Apr 2025 22:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30218</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the x-middleware-subrequest-id which persisted across multiple incoming requests. However, this subrequest ID is sent to all requests, even if the destination is not the same host as the Next.js application. Initiating a fetch request to a third-party within Middleware will send th…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31137 – React Router is a multi-strategy router for React bridging the gap from React 18...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31137</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31137</guid>
    <pubDate>Tue, 01 Apr 2025 19:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31137</strong></p>
  <p>React Router is a multi-strategy router for React bridging the gap from React 18 to React 19. There is a vulnerability in Remix/React Router that affects all Remix 2 and React Router 7 consumers using the Express adapter. Basically, this vulnerability allows anyone to spoof the URL used in an incoming Request by putting a URL pathname in the port section of a URL that is part of a Host or X-Forwa…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31137">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30210 – Bruno is an open source IDE for exploring and testing APIs. Prior to 1.39.1, the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30210</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30210</guid>
    <pubDate>Tue, 01 Apr 2025 15:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30210</strong></p>
  <p>Bruno is an open source IDE for exploring and testing APIs. Prior to 1.39.1, the custom tool-tip components which internally use react-tooltip were setting the content (in this case the Environment name) as raw HTML which then gets injected into DOM on hover. This, combined with loose Content Security Policy restrictions, allowed any valid HTML text containing inline script to get executed on hov…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30210">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-29927 – Next.js is a React framework for building full-stack web applications. Starting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29927</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29927</guid>
    <pubDate>Fri, 21 Mar 2025 15:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-29927</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to a safe version is infeasible, it is recommend that you prevent external user requests which contain th…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29927">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-25187 – Joplin is a free, open source note taking and to-do application, which can handl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25187</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25187</guid>
    <pubDate>Fri, 07 Feb 2025 23:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-25187</strong></p>
  <p>Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by adding note titles to the document using React's `dangerouslySetInnerHTML`, without first escaping HTML entities. Joplin lacks a Content-Security-Policy with a restrictive `script-src`. This allows arbitrary JavaScript execution via in…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25187">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-56332 – Next.js is a React framework for building full-stack web applications. Starting ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56332</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56332</guid>
    <pubDate>Fri, 03 Jan 2025 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-56332</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions 13.5.8, 14.2.21, and 15.1.2, Next.js is vulnerable to a Denial of Service (DoS) attack that allows attackers to construct requests that leaves requests to Server Actions hanging until the hosting provider cancels the function execution. This vulnerability can also be used as a D…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56332">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-51479 – Next.js is a React framework for building full-stack web applications. In affect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51479</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51479</guid>
    <pubDate>Tue, 17 Dec 2024 19:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-51479</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed for pages directly under the application's root directory. For example: * [Not affected] `https://example.com/` * [Affected] `https://example.com/foo` * [Not affected]…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51479">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-51750 – Element is a Matrix web client built using the Matrix React SDK. A malicious hom...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51750</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51750</guid>
    <pubDate>Tue, 12 Nov 2024 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-51750</strong></p>
  <p>Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over federation which can prevent Element Web and Desktop from rendering single messages or the entire room containing them. This was patched in Element Web and Desktop 1.11.85.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51750">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-51749 – Element is a Matrix web client built using the Matrix React SDK. Versions of Ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51749</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51749</guid>
    <pubDate>Tue, 12 Nov 2024 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-51749</strong></p>
  <p>Element is a Matrix web client built using the Matrix React SDK. Versions of Element Web and Desktop earlier than 1.11.85 do not check if thumbnails for attachments, stickers and images are coherent. It is possible to add thumbnails to events trigger a file download once clicked. Fixed in element-web 1.11.85.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-451</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51749">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52004 – MediaCMS is an open source video and media CMS, written in Python/Django and Rea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52004</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52004</guid>
    <pubDate>Fri, 08 Nov 2024 23:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52004</strong></p>
  <p>MediaCMS is an open source video and media CMS, written in Python/Django and React, featuring a REST API. MediaCMS has been prone to vulnerabilities that upon special cases can lead to remote code execution. All versions before v4.1.0 are susceptible, and users are highly recommended to upgrade. The vulnerabilities are related with insufficient input validation while uploading media content. The…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52004">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47824 – matrix-react-sdk is react-based software development kit for inserting a Matrix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47824</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47824</guid>
    <pubDate>Tue, 15 Oct 2024 16:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47824</strong></p>
  <p>matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starting in version 3.18.0 and before 3.102.0, matrix-react-sdk allows a malicious homeserver to potentially steal message keys for a room when a user invites another user to that room, via injection of a malicious device controlled by the homeserver. This is possible because matrix-r…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47824">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47779 – Element is a Matrix web client built using the Matrix React SDK. Element Web ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47779</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47779</guid>
    <pubDate>Tue, 15 Oct 2024 16:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47779</strong></p>
  <p>Element is a Matrix web client built using the Matrix React SDK. Element Web versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access token becoming exposed to third parties. At least one vector has been identified internally, involving malicious widgets, but other vectors may exist. Note that despite superficial similarity to CVE-…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47779">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-47831 – Next.js is a React Framework for the Web. Cersions on the 10.x, 11.x, 12.x, 13.x...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47831</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47831</guid>
    <pubDate>Mon, 14 Oct 2024 18:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-47831</strong></p>
  <p>Next.js is a React Framework for the Web. Cersions on the 10.x, 11.x, 12.x, 13.x, and 14.x branches before version 14.2.7 contain a vulnerability in the image optimization feature which allows for a potential Denial of Service (DoS) condition which could lead to excessive CPU consumption. Neither the `next.config.js` file that is configured with `images.unoptimized` set to `true` or `images.loade…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47831">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-46982 – Next.js is a React framework for building full-stack web applications. By sendin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46982</guid>
    <pubDate>Tue, 17 Sep 2024 22:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-46982</strong></p>
  <p>Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non-dynamic server-side rendered route in the pages router (this does not affect the app router). When this crafted request is sent it could coerce Next.js to cache a route that is meant to not be cached and send a `Cache-Control: s-maxage=1, stale-whil…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-42347 – matrix-react-sdk  is a react-based SDK for inserting a Matrix chat/voip client i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42347</guid>
    <pubDate>Tue, 06 Aug 2024 18:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-42347</strong></p>
  <p>matrix-react-sdk  is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server. This was patched in matrix-react-sdk 3.105.0. Deployments that trust their homeservers, as we…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-359</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-6578 – A stored cross-site scripting (XSS) vulnerability exists in aimhubio/aim version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6578</guid>
    <pubDate>Mon, 29 Jul 2024 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-6578</strong></p>
  <p>A stored cross-site scripting (XSS) vulnerability exists in aimhubio/aim version 3.19.3. The vulnerability arises from the improper neutralization of input during web page generation, specifically in the logs-tab for runs. The terminal output logs are displayed using the `dangerouslySetInnerHTML` function in React, which is susceptible to XSS attacks. An attacker can exploit this vulnerability by…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-40631 – Plate media is an open source, rich-text editor for React. Editors that use `Med...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40631</guid>
    <pubDate>Mon, 15 Jul 2024 19:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-40631</strong></p>
  <p>Plate media is an open source, rich-text editor for React. Editors that use `MediaEmbedElement` and pass custom `urlParsers` to the `useMediaState` hook may be vulnerable to XSS if a custom parser allows `javascript:`, `data:` or `vbscript:` URLs to be embedded. Editors that do not use `urlParsers` and consume the `url` property directly may also be vulnerable if the URL is not sanitised. The def…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39903 – Solara is a pure Python, React-style framework for scaling Jupyter and web apps...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39903</guid>
    <pubDate>Fri, 12 Jul 2024 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39903</strong></p>
  <p>Solara is a pure Python, React-style framework for scaling Jupyter and web apps. A Local File Inclusion (LFI) vulnerability was identified in widgetti/solara, in version <1.35.1, which was fixed in version 1.35.1. This vulnerability arises from the application's failure to properly validate URI fragments for directory traversal sequences such as '../' when serving static files. An attacker can ex…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39693 – Next.js is a React framework. A Denial of Service (DoS) condition was identified...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39693</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39693</guid>
    <pubDate>Wed, 10 Jul 2024 20:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39693</strong></p>
  <p>Next.js is a React framework. A Denial of Service (DoS) condition was identified in Next.js. Exploitation of the bug can trigger a crash, affecting the availability of the server. his vulnerability was resolved in Next.js 13.5 and later.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39693">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-36937 – In the Linux kernel, the following vulnerability has been resolved:

xdp: use fl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36937</guid>
    <pubDate>Thu, 30 May 2024 16:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-36937</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  xdp: use flags field to disambiguate broadcast redirect  When redirecting a packet using XDP, the bpf_redirect_map() helper will set up the redirect destination information in struct bpf_redirect_info (using the __bpf_xdp_redirect_map() helper function), and the xdp_do_redirect() function will read this information after the XDP…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-34351 – Next.js is a React framework that can provide building blocks to create web appl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34351</guid>
    <pubDate>Tue, 14 May 2024 15:38:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-34351</strong></p>
  <p>Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the `Host` header is modified, and the below conditions are also met, an attacker may be able to make requests that appear to be originating from the Next.js application server itself. The required conditions are…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-34350 – Next.js is a React framework that can provide building blocks to create web appl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34350</guid>
    <pubDate>Tue, 14 May 2024 15:38:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-34350</strong></p>
  <p>Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafted HTTP request meant that requests are treated as both a single request, and two separate requests by Next.js, leading to desynchronized responses. This led to a response queue poisoning vulnerability in the affected Next.js versions. For a request t…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-34342 – react-pdf displays PDFs in React apps. If PDF.js is used to load a malicious PDF...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34342</guid>
    <pubDate>Tue, 07 May 2024 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-34342</strong></p>
  <p>react-pdf displays PDFs in React apps. If PDF.js is used to load a malicious PDF, and PDF.js is configured with `isEvalSupported` set to `true` (which is the default value), unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain. This vulnerability is fixed in 7.7.3 and 8.0.2.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34342">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
