React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time
Published Dec 31, 2018
6.1
MEDIUMCVSS 3.1
EPSS 3.43%
Description
React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2, 16.2.1, 16.3.3, and 16.4.2.
Affected products
-
- Version 16.0.0StatusaffectedConstraints<unspecified
- Version 16.0.1StatusaffectedConstraints-
- Version 16.1.0StatusaffectedConstraints<unspecified
- Version 16.1.2StatusaffectedConstraints-
- Version 16.2.0StatusaffectedConstraints<unspecified
- Version 16.2.1StatusaffectedConstraints-
- Version 16.3.0StatusaffectedConstraints<unspecified
- Version 16.3.3StatusaffectedConstraints-
- Version 16.4.0StatusaffectedConstraints<unspecified
- Version 16.4.2StatusaffectedConstraints-
- Version unspecifiedStatusunaffectedConstraints<16.0.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| React-Dom | n/a |
|
No data.
No Red Hat product state for this CVE.
react-dom
npm
Introduced 16.3.0 Fixed 16.3.3react-dom
npm
Introduced 16.4.0 Fixed 16.4.2react-dom
npm
Introduced 16.0.0 Fixed 16.0.1react-dom
npm
Introduced 16.1.0 Fixed 16.1.2react-dom
npm
Introduced 16.2.0 Fixed 16.2.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | react-dom | 16.3.0 | 16.3.3 |
| npm | react-dom | 16.4.0 | 16.4.2 |
| npm | react-dom | 16.0.0 | 16.0.1 |
| npm | react-dom | 16.1.0 | 16.1.2 |
| npm | react-dom | 16.2.0 | 16.2.1 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed May 6, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (45 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.43% (0.03426) | 88.53th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.43% (0.03426) | 87.34th | v5 (v2026.06.15) |
| Mar 4, 2026 | 10.57% (0.10572) | 93.14th | v4 (v2025.03.14) |
| Mar 1, 2026 | 13.18% (0.13176) | 94.02th | v4 (v2025.03.14) |
| Feb 4, 2026 | 16.68% (0.16684) | 94.75th | v4 (v2025.03.14) |
| Feb 1, 2026 | 13.18% (0.13176) | 93.97th | v4 (v2025.03.14) |
| Jan 4, 2026 | 16.68% (0.16684) | 94.71th | v4 (v2025.03.14) |
| Jan 1, 2026 | 13.18% (0.13176) | 93.94th | v4 (v2025.03.14) |
| Dec 4, 2025 | 16.68% (0.16684) | 94.67th | v4 (v2025.03.14) |
| Dec 1, 2025 | 13.18% (0.13176) | 93.90th | v4 (v2025.03.14) |
| Nov 21, 2025 | 16.68% (0.16684) | 94.66th | v4 (v2025.03.14) |
| Nov 18, 2025 | 6.93% (0.06935) | 90.51th | v4 (v2025.03.14) |
| Nov 4, 2025 | 16.68% (0.16684) | 94.65th | v4 (v2025.03.14) |
| Nov 1, 2025 | 13.18% (0.13176) | 93.87th | v4 (v2025.03.14) |
| Oct 13, 2025 | 16.68% (0.16684) | 94.61th | v4 (v2025.03.14) |
| Oct 7, 2025 | 23.03% (0.23028) | 95.72th | v4 (v2025.03.14) |
| Oct 5, 2025 | 18.75% (0.18749) | 95.04th | v4 (v2025.03.14) |
| Oct 4, 2025 | 21.11% (0.21109) | 95.45th | v4 (v2025.03.14) |
| Oct 1, 2025 | 19.26% (0.19258) | 95.18th | v4 (v2025.03.14) |
| Sep 25, 2025 | 21.11% (0.21109) | 95.47th | v4 (v2025.03.14) |
| Sep 4, 2025 | 18.05% (0.18055) | 94.92th | v4 (v2025.03.14) |
| Sep 1, 2025 | 16.50% (0.16500) | 94.68th | v4 (v2025.03.14) |
| Aug 4, 2025 | 18.05% (0.18055) | 94.90th | v4 (v2025.03.14) |
| Aug 1, 2025 | 16.50% (0.16500) | 94.66th | v4 (v2025.03.14) |
| Jul 30, 2025 | 18.05% (0.18055) | 94.89th | v4 (v2025.03.14) |
| Jul 4, 2025 | 16.00% (0.16000) | 94.47th | v4 (v2025.03.14) |
| Jul 1, 2025 | 14.58% (0.14584) | 94.17th | v4 (v2025.03.14) |
| Jun 4, 2025 | 16.00% (0.16000) | 94.42th | v4 (v2025.03.14) |
| Jun 1, 2025 | 14.58% (0.14584) | 94.14th | v4 (v2025.03.14) |
| May 5, 2025 | 16.00% (0.16000) | 94.36th | v4 (v2025.03.14) |
| May 1, 2025 | 14.58% (0.14584) | 94.11th | v4 (v2025.03.14) |
| Mar 30, 2025 | 16.00% (0.16000) | 94.21th | v4 (v2025.03.14) |
| Mar 29, 2025 | 31.91% (0.31907) | 94.99th | v4 (v2025.03.14) |
| Mar 28, 2025 | 16.00% (0.16000) | 94.22th | v4 (v2025.03.14) |
| Mar 27, 2025 | 31.91% (0.31907) | 96.19th | v4 (v2025.03.14) |
| Mar 20, 2025 | 16.00% (0.16000) | 94.26th | v4 (v2025.03.14) |
| Mar 19, 2025 | 37.20% (0.37203) | 96.70th | v4 (v2025.03.14) |
| Mar 17, 2025 | 14.02% (0.14021) | 93.82th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.08% (0.00085) | 38.03th | v3 (v2023.03.01) |
| Jun 21, 2024 | 0.08% (0.00084) | 36.24th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.08% (0.00084) | 34.21th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.56% (0.02561) | 82.01th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.56% (0.02561) | 61.74th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.74% (0.02742) | 63.06th | v5 (v2026.06.15) |
| Apr 14, 2021 | 2.74% (0.02742) | 0.00th | v1 |
References (6)
- https://github.com/advisories/GHSA-mvjj-gqq2-p4hw Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-6341
- https://reactjs.org/blog/2018/08/01/react-v-16-4-2.html x_refsource_MISCVendor Advisory
- https://snyk.io/vuln/npm:react-dom:20180802
- https://twitter.com/reactjs/status/1024745321987887104 x_refsource_MISCVendor Advisory
- https://www.npmjs.com/advisories/1421
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-mvjj-gqq2-p4hw | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-6341 | ||
| https://reactjs.org/blog/2018/08/01/react-v-16-4-2.html | x_refsource_MISCVendor Advisory | |
| https://snyk.io/vuln/npm:react-dom:20180802 | ||
| https://twitter.com/reactjs/status/1024745321987887104 | x_refsource_MISCVendor Advisory | |
| https://www.npmjs.com/advisories/1421 |
Change history (0)
No recorded changes yet.