Summary
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
Advisory details
This is a follow up to https://github.com/remix-run/react-router/security/advisories/GHSA-8x6r-g9mw-2r78 that covers additional reported scenarios in which the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times.
[!NOTE] This only impacts Framework Mode applications. This does not impact your application if you are using Declarative or Data Mode.
References
- https://github.com/advisories/GHSA-chx6-hx7r-mcp5
- https://github.com/remix-run/react-router/security/advisories/GHSA-chx6-hx7r-mcp5
- https://github.com/remix-run/react-router/pull/15186
- https://github.com/remix-run/react-router/commit/09e6020d1950e54f361f7ad00938ecd4dde60929
- https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180
- https://github.com/remix-run/react-router/releases/tag/react-router@7.18.0
Related vulnerabilities
All Supply chain →- MEDIUMCVE-2026-81723
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()`
- MEDIUMCVE-2026-45822
decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input
- HIGHCVE-2026-55099
icalendar has Algorithmic Complexity in Equality
- HIGHCVE-2026-71491
sqlparse: Quadratic O(n²) DoS in group_comments
- HIGHGHSA-gm3r-q2wp-hw87
Shescape: Quadratic-time denial of service in the flag-protection
- HIGHCVE-2026-59885
pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service