Vendor
medium
advisory
React Router RSC Mode CSRF Bypass
1 TTP 1 CVEA high-severity Cross-Site Request Forgery (CSRF) bypass vulnerability in React Router's unstable React Server Components (RSC) APIs allows for action execution before a 400 response, impacting applications utilizing these specific APIs.
react-router
react
router
csrf
web-application
vulnerability
1t
1c
medium
advisory
React Router Denial of Service via Inefficient Route Matching (CVE-2026-55685)
1 TTPAn unauthenticated attacker can exploit CVE-2026-55685 in React Router versions 7.0.0 through 7.17.x, when used in Framework Mode applications, to cause a denial-of-service condition by repeatedly accessing the manifest endpoint, leading to heavy server load and slow response times.
react-router
web-vulnerability
denial-of-service
npm
1t