CVE-2026-34077

Source
https://cve.org/CVERecord?id=CVE-2026-34077
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34077.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-34077
Aliases
Downstream
Related
Published
2026-06-02T17:31:35.579Z
Modified
2026-08-05T03:32:14.147597143Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
React Router vulnerable to Denial of Service via reflected user input in single-fetch
Details

React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in version 7.13.2.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34077.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "7.0.0"
                },
                {
                    "fixed": "7.14.0"
                },
                {
                    "fixed": "3.0.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "introduced": "7.7.0"
                },
                {
                    "fixed": "7.13.1"
                }
            ],
            "source": "DESCRIPTION"
        }
    ],
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-770"
    ]
}
References

Affected packages

Git / github.com/jacob-ebey/turbo-stream

Affected ranges

Type
GIT
Repo
https://github.com/jacob-ebey/turbo-stream
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:turbo-stream:turbo_stream:*:*:*:*:*:node.js:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.0.0"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v1.*
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0
v1.1.1
v1.2.0
v1.2.1
v2.*
v2.0.0
v2.0.1
v2.1.0
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.4.0
v2.4.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34077.json"