Denial of Service Vulnerability in React Router by Remix Run
CVE-2026-55685

8.7HIGH

Key Information:

Vendor

Remix-run

Vendor
CVE Published:
27 July 2026

What is CVE-2026-55685?

A vulnerability in React Router versions 7.0.0 to 7.17.0 allows unauthenticated targeted requests to the manifest endpoint, potentially leading to a denial of service. This could overload the server and negatively impact response times. Notably, applications utilizing Declarative Mode or Data Mode are not affected. This issue was addressed in version 7.18.0, where the necessary patches have been implemented to secure the affected versions.

Affected Version(s)

react-router >= 7.0.0, < 7.18.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.