@remix-run/server-runtime
npm3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @remix-run/server-runtimepage 1 of 1
- CVE-2026-22030MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.17.32026-01-10
React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, React Router (or Remix v2) is vulnerable to CSRF attacks on document POST requests to UI routes when using ser…
- CVE-2026-42342HIGHCVSS 7.5EG 7.5✓ Fixed in 2.17.52026-06-02
React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can consume disproportionate server resources via unbounded path…
- CVE-2026-53663LOWCVSS 3.1EG 3.1✓ Fixed in 2.17.52026-06-15
React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were bypassed on PUT/PATCH/DELETE requests. This is a low severity vulnerab…
Check whether @remix-run/server-runtime is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @remix-run/server-runtime CVEs against the assets you own.
Start Free Scan →