Cross-site request forgery in server-runtime - CVE-2026-22030
Published: June 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to origin validation error in action and server action request processing when handling document POST requests to UI routes. A remote attacker can cause the victim's browser to send a crafted cross-site request to perform cross-site request forgery attacks.
The issue affects applications using server-side route action handlers in framework mode or React Server Actions in unstable RSC modes. Declarative mode and data mode are not affected.
Affected software
IBM Fusion HCI
React Router
Data Cataloging
How to mitigate CVE-2026-22030
IBM Fusion HCI - update to 2.13.0
React Router - update to 7.12.0
Data Cataloging - update to 2.5.3