Junglewise Threat Intelligence

CVE-2026-55685: remix-run react-router resource consumption in manifest endpoint

CVE-2026-55685 · Severity: high · CVSS 4 · Published 2026-07-27

Technologies: Remix-Run React Router.

Executive brief

React Router, a popular library for managing navigation in React web applications, contains a vulnerability in its manifest endpoint. An unauthenticated attacker can send specially crafted requests to this endpoint to consume excessive server resources. This can lead to significant performance degradation or a complete service outage for legitimate users.

Technical details

A vulnerability classified as uncontrolled resource consumption (CWE-400) and inefficient algorithmic complexity (CWE-407) exists in React Router's manifest endpoint. In affected versions (7.0.0 to 7.17.0), the endpoint can be accessed via unauthenticated network requests that trigger expensive route-matching operations. This allows a remote attacker to perform a Denial of Service (DoS) attack by saturating server CPU/memory. The issue specifically affects applications not using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter). A fix was introduced in version 7.18.0 by optimizing route matching internals and manifest discovery.

Affected products

  • remix-run react-router >= 7.0.0, < 7.18.0

Timeline

  • 2026-06-15: patched: Fix committed to main branch
  • 2026-07-27: advisory: CVE published to NVD

References