Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 npm

React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint

GHSA-8x6r-g9mw-2r78 · CVE-2026-42342

Published · Modified

Description

There exists a potential DOS attack vector in React Router Framework Mode applications (as well as Remix v2.10.0 - 2.17.4). Certain requests can be crafted to consume disproportionate resources on the server, resulting in response time degredation and/or service unavailability for end users.

[!NOTE]
This does not impact your React Router application if you are using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>).

Ready to move

Start Securing

Free, no credit card | First findings in minutes