CVE-2026-53666
CVE-2026-53666: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityMedium6.1
Medium [CVE-2026-53666] Information disclosure via client-side constructor execution
CVE-2026-53666Source published Source updated
React Router is a router for React. In versions 6.4.0 through 7.17.0, if application code was written in a way that allows attacker-supplied input to overwrite certain aspects of errors caught by the SSR process, then it was possible for an attacker to trigger unexpected constructor execution on the client, which would in turn trigger an outbound network request. This is only possible with very specific (and unlikely) application-layer code. Note that this does not impact an application if it is using Declarative Mode. It only impacts Framework Mode and Data Mode applications that perform manual SSR/hydration. This issue has been fixed in version 7.18.0. This execution could lead to an outbound network request, potentially resulting in limited information disclosure or unintended network…
- Affected products in this advisory
- Cryostat 4
- Exploit Intelligence
- Gatekeeper 3
- Migration Toolkit for Applications 8
41 more entries in the full advisory.
- Source-reported affected versions
- 6.4.0
- 7.17.0
- Source-reported fixed versions
- 7.18.0
- Mitigation guidance
- To mitigate this issue, ensure that custom application code does not permit attacker-controlled input to modify error objects during server-side rendering (SSR) when using React Router in Framework or Data Modes. Review and harden application-layer error handling to prevent such overwrites. Applications not requiring Framework or Data Mode SSR should consider utilizing Declarative Mode, which is unaffected.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.