GHSA-qwww-vcr4-c8h2

Updated on 24 Jul 2026

Severity

Awaiting Analysis

Details

Overview

About vulnerability

This is a follow up to CVE-2026-22030 to address related CSRF flows in unstable RSC code paths.

> [!NOTE] > This only affects your application if you are using the unstable RSC APIs

Details

Affected product:
React
Affected packages:
react-router-dom @ 7.5.1 (+66 more)