Medium [CVE-2026-53667] Untrusted redirects due to missing protocol validation
This medium-severity Red Hat Linux advisory covers CVE-2026-53667 affecting Exploit Intelligence, Network Observability Operator, OpenShift Lightspeed.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources.
This issue is a follow up to CVE-2026-53667, and only affects consuming applications if they are using the unstable RSC APIs. This issue has been fixed in version 7.18.0.
The RSCErrorHandler component, used in applications leveraging unstable React Server Components (RSC) Application Programming Interfaces (APIs), is missing crucial protocol validation. This vulnerability allows an attacker to redirect users to untrusted external websites.
Such redirects can lead to information disclosure or facilitate phishing attacks, potentially exposing sensitive user data. Red Hat's CVSS score (6.9, AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N) matches the upstream/CVE.org self-assigned score exactly, so no Red Hat-specific re-scoring was applied.
Red Hat severity: Moderate — CVSS 6.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N). Weakness: CWE-601.
Affected products named by the advisory: Exploit Intelligence; Network Observability Operator; OpenShift Lightspeed; OpenShift Pipelines; and 8 more.
- 7.11.0
- 7.17.0
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Mitigation checklist
- There is no mitigation available other than upgrading to react-router/react-router-dom 7.18.0 or later once the fix is packaged in the affected Red Hat products. Products that do not use React Router's unstable RSC APIs are not affected regardless of the bundled react-router version.
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.