Skip to content
VulniPulse
Advisory severityMedium6.1Red Hat Linux

Medium [CVE-2026-53666] Information disclosure via client-side constructor execution

This medium-severity Red Hat Linux advisory covers CVE-2026-53666 affecting Cryostat 4, Exploit Intelligence, Gatekeeper 3.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-53666 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

React Router is a router for React.

In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for an attacker to trigger unexpected constructor execution on the client, which would in turn trigger an outbound network request.

This is only possible with very specific (and unlikely) application-layer code. Note that this does not impact an application if it is using Declarative Mode.

It only impacts Framework Mode and Data Mode applications that perform manual SSR/hydration. This issue has been fixed in version 7.18.0.

This execution could lead to an outbound network request, potentially resulting in limited information disclosure or unintended network activity. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

Weakness: CWE-502.

Affected products named by the advisory: Cryostat 4; Exploit Intelligence; Gatekeeper 3; Migration Toolkit for Applications 8; and 41 more.

Affected products named by the advisory: Migration Toolkit for Containers; Migration Toolkit for Virtualization; Multicluster Engine for Kubernetes; Network Observability Operator; and 37 more.

Affected versions
  • 6.4.0
  • 7.17.0

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Fixed versions
  • 7.18.0

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • To mitigate this issue, ensure that custom application code does not permit attacker-controlled input to modify error objects during server-side rendering (SSR) when using React Router in Framework or Data Modes. Review and harden application-layer error handling to prevent such overwrites. Applications not requiring Framework or Data Mode SSR should consider utilizing Declarative Mode, which is unaffected.

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.