Input validation error in React Router - CVE-2026-40181
Published: June 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect users to an external domain.
The vulnerability exists due to improper input validation in the redirect function when processing URLs with a path starting with // that is reinterpreted as a protocol-relative URL. A remote attacker can supply a crafted URL to redirect users to an external domain.
This does not affect applications using declarative mode.
Affected software
IBM Cloud Transformation Advisor
IBM SPSS Collaboration and Deployment Services
Application Modernization Accelerator
How to mitigate CVE-2026-40181
IBM Cloud Transformation Advisor - update to 5.0.0
Application Modernization Accelerator - update to 5.0.0
IBM SPSS Collaboration and Deployment Services - update to 9.0.0.0.0 IF13