Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53667

Опубликовано: 27 июл. 2026
Источник: redhat
CVSS3: 6.9
EPSS Низкий

Описание

A flaw was found in React Router. The RSCErrorHandler component, used in applications leveraging unstable React Server Components (RSC) Application Programming Interfaces (APIs), is missing crucial protocol validation. This vulnerability allows an attacker to redirect users to untrusted external websites. Such redirects can lead to information disclosure or facilitate phishing attacks, potentially exposing sensitive user data.

Отчет

React Router (npm packages react-router and react-router-dom) versions 7.11.0 through 7.17.0 contain a missing protocol validation flaw in the RSCErrorHandler component. This component is only used by applications that opt in to React Router's unstable React Server Components (RSC) APIs; applications that do not use the RSC APIs are not reachable through this code path. Where the RSC APIs are in use, an attacker can supply a URL that bypasses protocol validation and redirect a victim to an untrusted external site, which can facilitate phishing or information disclosure. This issue is fixed upstream in react-router/react-router-dom 7.18.0. This flaw is only reachable in Red Hat products that both bundle an affected version of react-router/react-router-dom in a web console or UI component AND make use of the unstable RSC APIs in that component's own code. Simply bundling react-router as a dependency does not by itself make a product exploitable; each console/UI must be independently assessed by its owning component team for RSC API usage. Red Hat's CVSS score (6.9, AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N) matches the upstream/CVE.org self-assigned score exactly, so no Red Hat-specific re-scoring was applied.

Меры по смягчению последствий

There is no mitigation available other than upgrading to react-router/react-router-dom 7.18.0 or later once the fix is packaged in the affected Red Hat products. Products that do not use React Router's unstable RSC APIs are not affected regardless of the bundled react-router version.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat-openshift-console-plugin-npmNot affected
Cryostat 4grafana-infinity-datasource-npmNot affected
Cryostat 4react-routerNot affected
Exploit Intelligenceexploit-intelligence-tech-preview/agent-client-rhel9Out of support scope
Gatekeeper 3gatekeeper/gatekeeper-rhel9Not affected
Migration Toolkit for Applications 8mta/mta-ui-rhel8Not affected
Migration Toolkit for Applications 8mta/mta-ui-rhel9Not affected
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Not affected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Not affected
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2507836react-router: React Router: Untrusted redirects due to missing protocol validation

EPSS

Процентиль: 28%
0.00354
Низкий

6.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.9
nvd
8 дней назад

React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up to CVE-2026-53667, and only affects consuming applications if they are using the unstable RSC APIs. This issue has been fixed in version 7.18.0.

CVSS3: 6.9
github
12 дней назад

React Router: RSCErrorHandler Missing Protocol Validation (XSS)

EPSS

Процентиль: 28%
0.00354
Низкий

6.9 Medium

CVSS3