CVE-2026-53669

React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)

React Router is a router for React. Versions 6.0.0 through 7.17.0 are vulnerable to Open Redirtect through use of backslashes in <Link> and useNavigate. This issue is a follow up to CVE-2025-68470 and has been fixed in version 7.18.0.


We have discovered 654 live websites that are affected by CVE-2026-53669.

Run a Free Instant Scan




Affected Software

Product  React Router DOM
Category JavaScript Libraries
Vulnerable Domains654 live websites (70% of React Router DOM install base)
Vulnerable Versions
  • from 6 through 7.18
Vulnerable Versions Count40 versions ( 69% of all versions)


Common Weakness Enumeration

CWE-601 URL Redirection to Untrusted Site ('Open Redirect')



Details

  • Published - Jul 27, 2026
  • Updated - Jul 28, 2026

Website Distribution by Country

Number of websites using CVE-2026-53669
United States241 websites



New Zealand225 websites
Germany51 websites
China14 websites
Singapore10 websites
Brazil9 websites
France9 websites
Japan9 websites
Russia9 websites
Cyprus7 websites

Website Distribution by TLD

Number of websites using CVE-2026-53669
.com249 websites
.net14 websites
.com.br13 websites
.ru9 websites
.org8 websites
.co7 websites
.de7 websites
.it5 websites
.nl5 websites
.se5 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-53669

Top websites that are affected by CVE-2026-53669. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States**,***
***.com United States**,***
***.com United States**,***
*****.com United States**,***
*.******.com China**,***
****.com United States**,***
****.******.com China**,***
*********.com United States***,***
*******.com United States***,***
*****.org United States***,***
See full domain list

FAQ

CVE-2026-53669 is URL Redirection to Untrusted Site ('Open Redirect') in React Router DOM
A total of 654 websites have been identified as vulnerable to CVE-2026-53669, based on global website indexing conducted by WebTechSurvey.
The React Router DOM is affected by the CVE-2026-53669 vulnerability.
React Router DOM versions up to 7.18 are vulnerable to CVE-2026-53669.
CVE-2026-53669 is resolved in version 7.18 of React Router DOM.