Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53663

Опубликовано: 22 июн. 2026
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were bypassed on PUT/PATCH/DELETE requests. This is a low severity vulnerability because modern browser protections (CORS preflight, SameSite cookies) already block the cross-origin attack vectors that this missing CSRF check would otherwise gate. This vulnerability is fixed in 7.15.1.

A flaw was found in React Router. Insufficient Cross-Site Request Forgery (CSRF) checks in the framework mode allow a remote attacker to bypass these protections on PUT, PATCH, and DELETE requests. This could lead to a low integrity impact, where an attacker might be able to perform unintended actions on behalf of a user. Modern browser security features, such as Cross-Origin Resource Sharing (CORS) preflight and SameSite cookies, significantly limit the practical exploitability of this vulnerability.

Отчет

This is a Low impact vulnerability. Insufficient Cross-Site Request Forgery (CSRF) checks in React Router's framework mode could allow an attacker to bypass protections on PUT, PATCH, and DELETE requests. However, modern browser security features like CORS preflight and SameSite cookies significantly reduce the practical exploitability of this flaw in typical Red Hat deployments.

Меры по смягчению последствий

Red Hat products that ship react-router are affected by this CSRF bypass in Framework Mode on PUT, PATCH, and DELETE requests. However, modern browser protections — CORS preflight checks and SameSite cookie defaults — significantly limit the practical exploitability of this flaw. No specific workaround is required. Updating to react-router 7.15.1 or later, when available in product updates, will fully resolve this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Interconnect 1qpid-dispatchNot affected
Cryostat 4cryostat-openshift-console-plugin-npmNot affected
Cryostat 4grafana-infinity-datasource-npmNot affected
Cryostat 4react-routerNot affected
Cryostat 4react-router-domNot affected
Cryostat 4react-router-dom-v5-compatNot affected
Exploit Intelligenceexploit-intelligence-tech-preview/agent-client-rhel9Fix deferred
Gatekeeper 3gatekeeper/gatekeeper-rhel9Not affected
Migration Toolkit for Applications 8mta/mta-ui-rhel8Not affected
Migration Toolkit for Applications 8mta/mta-ui-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-352
https://bugzilla.redhat.com/show_bug.cgi?id=2491492react-router: @remix-run/server-runtime: React Router: Insufficient CSRF protection allows integrity impact

EPSS

Процентиль: 4%
0.00148
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
nvd
около 1 месяца назад

React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were bypassed on PUT/PATCH/DELETE requests. This is a low severity vulnerability because modern browser protections (CORS preflight, SameSite cookies) already block the cross-origin attack vectors that this missing CSRF check would otherwise gate. This vulnerability is fixed in 7.15.1.

CVSS3: 3.1
github
около 2 месяцев назад

React Router: Potential CSRF via PUT/PATCH/DELETE document requests

EPSS

Процентиль: 4%
0.00148
Низкий

3.1 Low

CVSS3