Denial of Service Vulnerability in React Router by Remix Run
CVE-2026-55685
8.7HIGH
What is CVE-2026-55685?
A vulnerability in React Router versions 7.0.0 to 7.17.0 allows unauthenticated targeted requests to the manifest endpoint, potentially leading to a denial of service. This could overload the server and negatively impact response times. Notably, applications utilizing Declarative Mode or Data Mode are not affected. This issue was addressed in version 7.18.0, where the necessary patches have been implemented to secure the affected versions.
Affected Version(s)
react-router >= 7.0.0, < 7.18.0
