CVE-2026-21884: React Router SSR XSS in ScrollRestoration
(updated )
A XSS vulnerability exists in in React Router’s <ScrollRestoration> API in Framework Mode when using the getKey/storageKey props during Server-Side Rendering which could allow arbitrary JavaScript execution during SSR if untrusted content is used to generate the keys.
[!NOTE] This does not impact applications if developers have disabled server-side rendering in Framework Mode, or if they are using Declarative Mode (
<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>).
References
- access.redhat.com/errata/RHSA-2026:19712
- access.redhat.com/errata/RHSA-2026:3782
- access.redhat.com/errata/RHSA-2026:3958
- access.redhat.com/errata/RHSA-2026:3960
- access.redhat.com/security/cve/CVE-2026-21884
- bugzilla.redhat.com/show_bug.cgi?id=2428421
- github.com/advisories/GHSA-8v8x-cx79-35w7
- github.com/remix-run/react-router/blob/react-router%407.12.0/CHANGELOG.md
- github.com/remix-run/react-router/commit/c89c32c562a7723c45ee71dab1c892acaf7a608d
- github.com/remix-run/react-router/pull/14705
- github.com/remix-run/react-router/security/advisories/GHSA-8v8x-cx79-35w7
- nvd.nist.gov/vuln/detail/CVE-2026-21884
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21884.json
Code Behaviors & Features
Detect and mitigate CVE-2026-21884 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →