HIGH 7.5 npm
React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint
GHSA-8x6r-g9mw-2r78 · CVE-2026-42342
Published · Modified
Description
There exists a potential DOS attack vector in React Router Framework Mode applications (as well as Remix v2.10.0 - 2.17.4). Certain requests can be crafted to consume disproportionate resources on the server, resulting in response time degredation and/or service unavailability for end users.
[!NOTE]
This does not impact your React Router application if you are using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>).
Ready to move
Start Securing
Free, no credit card | First findings in minutes