High severity7.5OSV Advisory· Published Jul 27, 2026· Updated Aug 3, 2026
CVE-2026-55685
CVE-2026-55685
Description
React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times. This issue is a follow up to CVE-2026-42342, and does not does not impact React Router applications using Declarative Mode () or Data Mode (createBrowserRouter/). This issue has been fixed in version 7.18.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
react-routernpm | >= 7.0.0, < 7.18.0 | 7.18.0 |
Affected products
57.0.0 - 7.17.0+ 1 more
- (no CPE)range: 7.0.0 - 7.17.0
- (no CPE)
- osv-coords2 versions
< 24.0.2-r7+ 1 more
- (no CPE)range: < 24.0.2-r7
- (no CPE)range: < 24.0.2-r7
Patches
Vulnerability mechanics
References
7- github.com/remix-run/react-router/commit/09e6020d1950e54f361f7ad00938ecd4dde60929nvdPatchWEB
- github.com/remix-run/react-router/pull/15186nvdIssue TrackingPatchWEB
- github.com/advisories/GHSA-chx6-hx7r-mcp5ghsaADVISORY
- github.com/remix-run/react-router/security/advisories/GHSA-8x6r-g9mw-2r78nvdThird Party Advisory
- github.com/remix-run/react-router/security/advisories/GHSA-chx6-hx7r-mcp5nvdThird Party AdvisoryWEB
- github.com/remix-run/react-router/blob/main/CHANGELOG.mdnvdRelease NotesWEB
- github.com/remix-run/react-router/releases/tag/[email protected]nvdRelease NotesWEB
News mentions
1- React Router: Five Moderate Vulnerabilities Including Open Redirects and XSS Disclosed TogetherVypr Intelligence · Jul 27, 2026