CVE-2026-33244

Aliases:GHSA-f22v-gfqf-p8f3CGA-6g55-vp2x-86rvCGA-7r45-pxhr-7h4pCGA-8jfc-86r7-456hCGA-frqq-386v-7q4m
Advisory lineage Upstream: 0 Downstream: 2
Analyzed
Published: 02 Jun 2026, 16:59
Last modified:02 Jun 2026, 17:28

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.4 MEDIUM
v3.1 (cve.org)
EPSS Score
0.14% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

02 Jun 2026, 16:59
Published
Vulnerability first disclosed
02 Jun 2026, 17:28
Last Modified
Vulnerability information updated

Description

React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` header value can permit Cross-Site Scripting (XSS) in the statically generated HTML files if the redirect location comes from an untrusted source. This does not impact applications using Declarative Mode (`<BrowserRouter>`) or Data Mode (`createBrowserRouter/<RouterProvider>`). This is patched in version 7.13.2.

CVSS Metrics

  • v3.1MEDIUMScore: 5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS Trends

Current EPSS score: 0.14% Percentile: 4%

Techniques & Countermeasures

  • CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Affected Systems

  • chainguardairflow-2

    all

  • chainguardairflow-core-2

    all

  • Npmreact-router

    ≥ 7.5.1, < 7.13.2

  • remix-runreact-router

    ≥ 7.5.1, < 7.13.2

  • shopifyreact-router

    ≥ 7.5.1, < 7.13.2

References (7)