← Vulnerability feed

Vulnerability record · CVE-2026-22030 · published 10 January 2026

CVE-2026-22030: Shopify react-router origin validation error vulnerability

Shopify · React Router

React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, React Router (or Remix v2) is vulnerable to CSRF attacks on document POST requests to UI routes when using server-side route action handlers in Framework Mode, or when using React Server Actions in the new unstable RSC modes. There is no impact if Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>) is being used. This issue has been patched in @remix-run/server-runtime version 2.17.3 and react-router version 7.12.0.

6.5 CVSS 3.1 Medium EPSS 0.19% · top 92.4% CWE-346 · Origin validation errorCWE-352 · Cross-site request forgery
6.5CVSS 3.1 base score
0.19%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, React Router (or Remix v2) is vulnerable to CSRF attacks on document POST requests to UI routes when using server-side route action handlers in Framework Mode, or when using React Server Actions in the new unstable RSC modes. There is no impact if Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>) is being used. This issue has been patched in @remix-run/server-runtime version 2.17.3 and react-router version 7.12.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-22030 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2026-55685Shopify react-router uncontrolled resource consumption vulnerabilityReact Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests t…EPSS 0.71%8.2CVE-2026-21884Shopify react-router cross-site scripting vulnerabilityReact Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in…EPSS 0.54%8.1CVE-2026-42211Shopify react-router deserialization of untrusted data vulnerabilityReact Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unaut…EPSS 0.62%7.6CVE-2025-59057Shopify react-router cross-site scripting vulnerabilityReact Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerab…EPSS 0.51%7.5CVE-2026-42342Shopify react-router uncontrolled resource consumption vulnerabilityReact Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime,…EPSS 0.46%7.5CVE-2026-34077Shopify react-router allocation without limits vulnerabilityReact Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is…EPSS 0.45%6.9CVE-2026-53668Shopify react-router cross-site scripting vulnerabilityReact Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable…EPSS 0.34%6.6CVE-2026-40181Shopify react-router open redirect vulnerabilityReact Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigg…EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2026-22030), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.