Medium severity6.9OSV Advisory· Published Jul 27, 2026· Updated Aug 3, 2026
CVE-2026-53667
CVE-2026-53667
Description
React Router is a router for React. In versions 7.11.0 through 7.17.0, the RSCErrorHandler is missing protocol validation, allowing for redirects from untrusted sources. This issue is a follow up to CVE-2026-53667, and only affects consuming applications if they are using the unstable RSC APIs. This issue has been fixed in version 7.18.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
react-routernpm | >= 7.11.0, < 7.18.0 | 7.18.0 |
Affected products
57.11.0 - 7.17.0+ 1 more
- (no CPE)range: 7.11.0 - 7.17.0
- (no CPE)
- osv-coords2 versions
< 24.0.2-r7+ 1 more
- (no CPE)range: < 24.0.2-r7
- (no CPE)range: < 24.0.2-r7
Patches
Vulnerability mechanics
References
6- github.com/remix-run/react-router/commit/ce596e823f0d7b883a433af1d5a839a8b9fe0242nvdPatchWEB
- github.com/remix-run/react-router/pull/15177nvdIssue TrackingPatchWEB
- github.com/advisories/GHSA-h8fp-f39c-q6mhghsaADVISORY
- github.com/remix-run/react-router/security/advisories/GHSA-h8fp-f39c-q6mhnvdThird Party AdvisoryWEB
- github.com/remix-run/react-router/blob/main/CHANGELOG.mdnvdRelease NotesWEB
- github.com/remix-run/react-router/releases/tag/[email protected]nvdRelease NotesWEB
News mentions
1- React Router: Five Moderate Vulnerabilities Including Open Redirects and XSS Disclosed TogetherVypr Intelligence · Jul 27, 2026