Описание
A flaw was found in React Router. The RSCErrorHandler component, used in applications leveraging unstable React Server Components (RSC) Application Programming Interfaces (APIs), is missing crucial protocol validation. This vulnerability allows an attacker to redirect users to untrusted external websites. Such redirects can lead to information disclosure or facilitate phishing attacks, potentially exposing sensitive user data.
Отчет
React Router (npm packages react-router and react-router-dom) versions 7.11.0 through 7.17.0 contain a missing protocol validation flaw in the RSCErrorHandler component. This component is only used by applications that opt in to React Router's unstable React Server Components (RSC) APIs; applications that do not use the RSC APIs are not reachable through this code path. Where the RSC APIs are in use, an attacker can supply a URL that bypasses protocol validation and redirect a victim to an untrusted external site, which can facilitate phishing or information disclosure. This issue is fixed upstream in react-router/react-router-dom 7.18.0. This flaw is only reachable in Red Hat products that both bundle an affected version of react-router/react-router-dom in a web console or UI component AND make use of the unstable RSC APIs in that component's own code. Simply bundling react-router as a dependency does not by itself make a product exploitable; each console/UI must be independently assessed by its owning component team for RSC API usage. Red Hat's CVSS score (6.9, AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N) matches the upstream/CVE.org self-assigned score exactly, so no Red Hat-specific re-scoring was applied.
Меры по смягчению последствий
There is no mitigation available other than upgrading to react-router/react-router-dom 7.18.0 or later once the fix is packaged in the affected Red Hat products. Products that do not use React Router's unstable RSC APIs are not affected regardless of the bundled react-router version.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Cryostat 4 | cryostat-openshift-console-plugin-npm | Not affected | ||
| Cryostat 4 | grafana-infinity-datasource-npm | Not affected | ||
| Cryostat 4 | react-router | Not affected | ||
| Exploit Intelligence | exploit-intelligence-tech-preview/agent-client-rhel9 | Out of support scope | ||
| Gatekeeper 3 | gatekeeper/gatekeeper-rhel9 | Not affected | ||
| Migration Toolkit for Applications 8 | mta/mta-ui-rhel8 | Not affected | ||
| Migration Toolkit for Applications 8 | mta/mta-ui-rhel9 | Not affected | ||
| Migration Toolkit for Containers | rhmtc/openshift-migration-ui-rhel8 | Not affected | ||
| Migration Toolkit for Virtualization | migration-toolkit-virtualization/mtv-console-plugin-rhel9 | Not affected | ||
| Multicluster Engine for Kubernetes | multicluster-engine/console-mce-rhel9 | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
6.9 Medium
CVSS3
Связанные уязвимости
React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up to CVE-2026-53667, and only affects consuming applications if they are using the unstable RSC APIs. This issue has been fixed in version 7.18.0.
React Router: RSCErrorHandler Missing Protocol Validation (XSS)
EPSS
6.9 Medium
CVSS3