Bug 2507839 (CVE-2026-53666) - CVE-2026-53666 react-router: React Router: Information disclosure via client-side constructor execution
Summary: CVE-2026-53666 react-router: React Router: Information disclosure via client-...
Keywords:
Status: NEW
Alias: CVE-2026-53666
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2507854 2507858 2507860 2507855 2507856 2507857 2507859 2507861
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-27 22:01 UTC by OSIDB Bzimport
Modified: 2026-08-15 08:28 UTC (History)
153 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-27 22:01:51 UTC
React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for an attacker to trigger unexpected constructor execution on the client, which would in turn trigger an outbound network request. This is only possible with very specific (and unlikely) application-layer code. Note that this does not impact an application if it is using Declarative Mode. It only impacts Framework Mode and Data Mode applications that perform manual SSR/hydration. This issue has been fixed in version 7.18.0.


Note You need to log in before you can comment on or make changes to this bug.