React Router Vulnerable to Cross-Site Scripting (XSS) via Redirect Location Mishandling (CVE-2026-22029)
39132
06 October 2026
06 October 2026
CLOSED
LOW
8.0 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
CVE-2026-22029
|
Brocade Security Advisory ID |
BSA-2026-3492 |
|
Component |
React Router |
|
CWE |
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
|
|
|
Summary
React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if you are creating redirect paths from untrusted content or via an open redirect. There is no impact if Declarative Mode (<BrowserRouter>) is being used. This issue has been patched in @remix-run/router version 1.23.2 and react-router version 7.12.0.
Products Affected
- No Brocade products are affected by this vulnerability
Products Not Affected
- Brocade FabricOS is not affected by this vulnerability
[VEX Justification: Vulnerable_code_not_in_execute_path] - Brocade SANnav is not affected by this vulnerability
[VEX Justification: Component_not_present] - Brocade ASCG is not affected by this vulnerability
[VEX Justification: Component_not_present]
Solution
- While the Brocade Fabric OS is not exploitable, a security update is provided in Brocade Fabric OS version 10.0.1
Revision History
|
Version |
Change |
Date |
|
1.0 |
Initial Publication |
10/06/2026 |
Disclaimer
THIS DOCUMENT IS PROVIDED ON AN AS-IS BASIS SOLELY FOR INFORMATIONAL PURPOSES AND DOES NOT IMPLY ANY KIND OF GUARANTY OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. YOUR USE OF THE INFORMATION CONTAINED HEREIN IS AT YOUR OWN RISK. ALL INFORMATION PROVIDED HEREIN IS BASED ON BROCADE'S CURRENT KNOWLEDGE AND UNDERSTANDING OF THE VULNERABILITY AND IMPACT TO BROCADE HARDWARE AND SOFTWARE PRODUCTS. BROCADE RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.