CVE-2026-42211 is a deserialization flaw in React Router affecting versions 7.0.0 through 7.14.1 when used in Framework Mode. The vulnerable code path is in the single-fetch transmission mechanism, which uses a vendored turbo-stream v2 implementation to serialize and deserialize complex JavaScript objects between client and server. The issue is specifically described in the error-handling logic of the single-fetch deserializer, where dynamically hydrating serialized JavaScript error subtypes can permit arbitrary constructor instantiation from crafted untrusted input. Under the documented attack conditions, this unsafe deserialization behavior can be chained with an existing prototype pollution vulnerability in the application code in a two-step attack that results in unauthorized remote code execution on the server. Applications using Declarative Mode or Data Mode are not affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote code execution vulnerability in React Router that requires chaining with an existing prototype pollution flaw to achieve shell access on remote servers.
An insecure deserialization vulnerability in React Router v7's single-fetch mechanism, specifically in the error-handling logic of its vendored turbo-stream v2 deserializer, allowing an unauthenticated remote attacker to instantiate arbitrary constructors via crafted serialized error payloads.
A remote code execution vulnerability in React Router Framework Mode affecting versions 7.0.0 through 7.14.1, where an existing prototype pollution flaw in application code can be leveraged in a two-step attack to achieve unauthorized RCE via external requests.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.