<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 06:42:41 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-21884 — React Router SSR XSS in ScrollRestoration</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-21884</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; remix-run react-router, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI 3.3, Red Hat Build of Kueue, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9&lt;/p&gt;
&lt;p&gt;React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router&amp;#39;s &amp;lt;ScrollRestoration&amp;gt; API in Framework Mode when using the getKey/storageKey props during Server-Side Rendering which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the keys. There is no impact if server-side rendering in Framework Mode is disabled, or if Declarative Mode (&amp;lt;BrowserRouter&amp;gt;) or Data Mode (createBrowserRouter/&amp;lt;RouterProvider&amp;gt;) is being used. This issue has been patched in @remix-run/react version 2.17.3 and react-router version 7.12.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; remix-run react-router, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Ansible Automation Platform 2.6, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI 3.3, Red Hat Build of Kueue, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9&lt;/p&gt;
&lt;p&gt;React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in in React Router&amp;#39;s &amp;lt;ScrollRestoration&amp;gt; API in Framework Mode when using the getKey/storageKey props during Server-Side Rendering which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the keys. There is no impact if server-side rendering in Framework Mode is disabled, or if Declarative Mode (&amp;lt;BrowserRouter&amp;gt;) or Data Mode (createBrowserRouter/&amp;lt;RouterProvider&amp;gt;) is being used. This issue has been patched in @remix-run/react version 2.17.3 and react-router version 7.12.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-21884</guid>
    </item>
  </channel>
</rss>
