Bug 2484115 (CVE-2026-42211)

Summary: CVE-2026-42211 react-router: React Router: Remote Code Execution via prototype pollution in Framework Mode
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aazores, abarbaro, abokovoy, abrianik, adudiak, akhatavk, alcohan, alizardo, amctagga, anjoseph, anpicker, anthomas, anujha, aoconnor, aos-team-art-private, aruklets, aschwart, asdas, asoldano, aszczucz, ataylor, bbaranow, bdettelb, bmaxwell, bniver, boliveir, brasmith, bstansbe, cdrage, cmah, cmyers, cochase, dbosanac, dbruscin, dhanak, dhanina, dkeler, dlofthou, dnakabaa, doconnor, dpaolell, dranck, drichtar, drosa, dschmidt, dymurray, eaguilar, ebaron, eborisov, ehelms, ehugonne, erezende, ewittman, fdeutsch, flucifre, fmariani, frenaud, ftrivino, ggainey, ggrzybek, gmalinko, gmeno, gotiwari, gparvin, groman, hasun, ibek, ibolton, istudens, ivassile, iweiss, janstey, jbalunas, jchui, jdelft, jfula, jgrulich, jhe, jhorak, jkoehler, jlanda, jmatsuok, jmatthew, jmontleo, jolong, jowilson, jpasqual, jprabhak, jraez, jreimann, jrokos, jtolenti, jupierce, juwatts, jwong, jwon, kaycoth, kbempah, kshier, ktsao, kvanderr, lball, lchilton, lcouzens, lgarciaa, lphiri, manissin, mbenjamin, mbiarnes, mcarlett, mdellweg, mdessi, mhackett, mhess, mhulan, mnovotny, mosmerov, mposolda, mrizzi, msvehla, mvyas, mwringe, nboldt, ngough, nipatil, nmoumoul, nwallace, nyancey, oaljalju, omaciel, ometelka, oramraz, osousa, pahickey, pantinor, parichar, pberan, pcattana, pcreech, pdelbell, pesilva, pgaikwad, pjindal, pmackay, ppalepu, ppostler, prdhamdh, prwatson, psrna, ptisnovs, rchan, rhaigner, rhel-process-autobot, rjohnson, rkubis, rmartinc, rstancel, rstepani, rushinde, sausingh, sdawley, sdoran, sfeifer, sghai, sidsharm, simaishi, slucidi, smaestri, smallamp, smcdonal, smullick, solenoci, sostapov, sseago, ssilvert, stcannon, sthorger, stirabos, suppawar, syedriko, tasato, tcunning, teagle, thason, thjenkin, tmalecek, tpopela, ttakamiy, vdosoudi, vereddy, veshanka, vlaad, vle, vmuzikar, vwilson, watson-tool-maintainers, wtam, xdharmai, yfang, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in React Router when operating in Framework Mode. A remote attacker could exploit an existing prototype pollution vulnerability within the application code. This could lead to unauthorized remote code execution (RCE) on the server through a two-step attack involving external requests. This vulnerability poses a significant risk, potentially allowing an attacker to take control of the affected system.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2502731, 2502733, 2502734, 2502732, 2502735, 2502736, 2502737, 2502738    
Bug Blocks:    

Description OSIDB Bzimport 2026-06-02 20:02:29 UTC
React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unauthorized remote code execution (RCE) through external requests. This attack requires the application code to have an existing prototype pollution vulnerability, which can then be leveraged in a 2-step attack where the second step triggers unauthorized RCE on the remote server. This does not impact applications using Declarative Mode (`<BrowserRouter>`) or Data Mode (`createBrowserRouter/<RouterProvider>`). This is patched in version 7.14.2.

Comment 2 David Hanina 2026-06-03 06:49:15 UTC
As FreeIPA goes, we can safely waive this one, as we use Declarative mode, which is not affected

Comment 5 errata-xmlrpc 2026-07-20 11:59:22 UTC
This issue has been addressed in the following products:

  Red Hat Data Grid 8.6.2

Via RHSA-2026:41951 https://access.redhat.com/errata/RHSA-2026:41951