Bug 2507839 (CVE-2026-53666)

Summary: CVE-2026-53666 react-router: React Router: Information disclosure via client-side constructor execution
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aazores, abarbaro, abokovoy, abrianik, alizardo, amctagga, anjoseph, anpicker, anthomas, anujha, aoconnor, aruklets, aschwart, asoldano, aszczucz, ataylor, bbaranow, bmaxwell, bniver, boliveir, brasmith, bstansbe, cdrage, cmah, cmyers, cochase, dbosanac, dbruscin, dkeler, dlofthou, dnakabaa, doconnor, dranck, drichtar, dschmidt, dymurray, eaguilar, ebaron, eborisov, ehelms, ehugonne, ewittman, flucifre, fmariani, frenaud, ftrivino, ggainey, ggrzybek, gmalinko, gmeno, gotiwari, gparvin, groman, hasun, ibolton, istudens, ivassile, iweiss, janstey, jchui, jfula, jhe, jhorak, jlanda, jmatsuok, jmatthew, jmontleo, jowilson, jpasqual, jprabhak, jraez, jreimann, jtolenti, juwatts, jwon, kaycoth, kbempah, kshier, ktsao, kvanderr, lball, lchilton, lcouzens, mbenjamin, mcarlett, mdellweg, mdessi, mhackett, mhulan, mosmerov, mposolda, mrizzi, msvehla, mvyas, mwringe, nboldt, ngough, nipatil, nmoumoul, nwallace, nyancey, oaljalju, ometelka, osousa, pantinor, parichar, pberan, pcattana, pcreech, pesilva, pgaikwad, pjindal, pmackay, prwatson, psrna, ptisnovs, rchan, rhaigner, rhel-process-autobot, rjohnson, rkubis, rmartinc, rstancel, rstepani, rushinde, sdawley, sfeifer, simaishi, slucidi, smallamp, solenoci, sostapov, sseago, ssilvert, stcannon, sthorger, suppawar, syedriko, tasato, tcunning, teagle, thason, thjenkin, tmalecek, vdosoudi, vereddy, veshanka, vmuzikar, watson-tool-maintainers, wtam, xdharmai, yfang, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in React Router. If an application is configured to allow attacker-supplied input to modify errors during server-side rendering (SSR), a remote attacker could trigger unexpected code execution on the client. This execution could lead to an outbound network request, potentially resulting in limited information disclosure or unintended network activity. This vulnerability specifically affects applications utilizing Framework Mode and Data Mode with manual SSR/hydration.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2507854, 2507858, 2507860, 2507855, 2507856, 2507857, 2507859, 2507861    
Bug Blocks:    

Description OSIDB Bzimport 2026-07-27 22:01:51 UTC
React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for an attacker to trigger unexpected constructor execution on the client, which would in turn trigger an outbound network request. This is only possible with very specific (and unlikely) application-layer code. Note that this does not impact an application if it is using Declarative Mode. It only impacts Framework Mode and Data Mode applications that perform manual SSR/hydration. This issue has been fixed in version 7.18.0.