Executive brief
React Router, a popular library for managing navigation in React web applications, contains a vulnerability in its manifest endpoint. An unauthenticated attacker can send specially crafted requests to this endpoint to consume excessive server resources. This can lead to significant performance degradation or a complete service outage for legitimate users.
Technical details
A vulnerability classified as uncontrolled resource consumption (CWE-400) and inefficient algorithmic complexity (CWE-407) exists in React Router's manifest endpoint. In affected versions (7.0.0 to 7.17.0), the endpoint can be accessed via unauthenticated network requests that trigger expensive route-matching operations. This allows a remote attacker to perform a Denial of Service (DoS) attack by saturating server CPU/memory. The issue specifically affects applications not using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter). A fix was introduced in version 7.18.0 by optimizing route matching internals and manifest discovery.
Affected products
- remix-run react-router >= 7.0.0, < 7.18.0
Timeline
- 2026-06-15: patched: Fix committed to main branch
- 2026-07-27: advisory: CVE published to NVD
References
- https://github.com/remix-run/react-router/blob/main/CHANGELOG.md
- https://github.com/remix-run/react-router/commit/09e6020d1950e54f361f7ad00938ecd4dde60929
- https://github.com/remix-run/react-router/pull/15186
- https://github.com/remix-run/react-router/releases/tag/react-router@7.18.0
- https://github.com/remix-run/react-router/security/advisories/GHSA-8x6r-g9mw-2r78
- https://github.com/remix-run/react-router/security/advisories/GHSA-chx6-hx7r-mcp5