CVE-2026-55685
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times. This issue is a follow up to CVE-2026-42342, and does not does not impact React Router applications using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>). This issue has been fixed in version 7.18.0.
| CWE | CWE-400 CWE-407 |
| Vendor | remix-run |
| Product | react-router |
| Published | Jul 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for remix-run react-router
Be the first to know when new unknown vulnerabilities affecting remix-run react-router are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
remix-run / react-router
>= 7.0.0, < 7.18.0
References
github.com: https://github.com/remix-run/react-router/security/advisories/GHSA-chx6-hx7r-mcp5 github.com: https://github.com/remix-run/react-router/security/advisories/GHSA-8x6r-g9mw-2r78 github.com: https://github.com/remix-run/react-router/pull/15186 github.com: https://github.com/remix-run/react-router/commit/09e6020d1950e54f361f7ad00938ecd4dde60929 github.com: https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180 github.com: https://github.com/remix-run/react-router/releases/tag/[email protected]