Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55685

Опубликовано: 27 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in React Router. An unauthenticated attacker can send targeted requests to the manifest endpoint, leading to a denial of service (DoS). This can put a heavy load on the server, significantly slowing down response times and impacting the availability of the application.

Отчет

React Router (npm packages react-router and @remix-run/server-runtime) versions 7.0.0 through 7.17.0 expose an unauthenticated manifest endpoint. Repeated, targeted requests to this endpoint place heavy load on the server and can degrade or deny service for other users. This issue is a follow-up to CVE-2026-42342 and is fixed upstream in react-router/@remix-run/server-runtime 7.18.0. This flaw only affects React Router's Framework Mode, applications that run a Node.js SSR server via @remix-run/server-runtime and serve the manifest endpoint. Applications using Declarative Mode () or Data Mode (createBrowserRouter/) do not run this server-side code path and are not affected. Simply bundling react-router does not by itself make a product exploitable; each console/UI component must be independently assessed by its owning team for Framework Mode usage and manifest endpoint exposure. Red Hat's CVSS score (6.5, CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) is lower than the CVE.org score because the affected React Router components in Red Hat products are used in internal console UIs that are deployed behind authenticated ingress, reducing the practical attack surface. This mirrors the same re-scoring applied to the predecessor flaw, CVE-2026-42342, for the same endpoint family.

Меры по смягчению последствий

Upgrade to react-router/@remix-run/server-runtime 7.18.0 or later once the fix is packaged in the affected Red Hat product. Where upgrading isn't immediately possible, rate-limiting or restricting access to the manifest endpoint at a reverse proxy or ingress layer can reduce exposure. Products that do not run React Router in Framework Mode (Declarative Mode or Data Mode only) are not affected regardless of the bundled react-router version.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat-openshift-console-plugin-npmNot affected
Cryostat 4grafana-infinity-datasource-npmNot affected
Cryostat 4react-routerNot affected
Exploit Intelligenceexploit-intelligence-tech-preview/agent-client-rhel9Affected
Gatekeeper 3gatekeeper/gatekeeper-rhel9Not affected
Migration Toolkit for Applications 8mta/mta-ui-rhel8Not affected
Migration Toolkit for Applications 8mta/mta-ui-rhel9Not affected
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Not affected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Not affected
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2507833react-router: @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests

EPSS

Процентиль: 44%
0.00577
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

nvd
8 дней назад

React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times. This issue is a follow up to CVE-2026-42342, and does not does not impact React Router applications using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>). This issue has been fixed in version 7.18.0.

github
11 дней назад

React Router: Unauthenticated Denial of Service via Inefficient Route Matching

EPSS

Процентиль: 44%
0.00577
Низкий

6.5 Medium

CVSS3