{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/remix/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["react-router (7.0.0 - 7.17.x)"],"_cs_severities":["medium"],"_cs_tags":["web-vulnerability","denial-of-service","react-router","npm"],"_cs_type":"advisory","_cs_vendors":["Remix"],"content_html":"\u003cp\u003eA high-severity denial-of-service (DoS) vulnerability, identified as CVE-2026-55685, affects \u003ccode\u003enpm/react-router\u003c/code\u003e versions 7.0.0 through 7.17.x. This vulnerability is a follow-up to a previously identified issue and specifically impacts applications configured in \u0026quot;Framework Mode.\u0026quot; An unauthenticated attacker can leverage this flaw by sending targeted, repetitive requests to the application's manifest endpoint. This exploitation leads to inefficient route matching processes, which consumes significant server resources, resulting in heavy server load, degraded response times, and ultimately a denial of service for legitimate users. Defenders using React Router in Framework Mode applications are advised to prioritize patching to mitigate this risk.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a web application utilizing \u003ccode\u003enpm/react-router\u003c/code\u003e configured in \u0026quot;Framework Mode.\u0026quot;\u003c/li\u003e\n\u003cli\u003eThe attacker identifies the application's manifest endpoint through reconnaissance or publicly available information.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts HTTP requests targeting this specific manifest endpoint.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a high volume of these targeted requests to the identified manifest endpoint.\u003c/li\u003e\n\u003cli\u003eDue to inefficient route matching within the vulnerable React Router versions, each request consumes disproportionately high server resources (CPU, memory).\u003c/li\u003e\n\u003cli\u003eThe continuous stream of requests causes the server to become overloaded, leading to resource exhaustion.\u003c/li\u003e\n\u003cli\u003eThe application's performance degrades significantly, resulting in slow response times or complete unresponsiveness.\u003c/li\u003e\n\u003cli\u003eLegitimate users are unable to access the service, resulting in a denial-of-service condition.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-55685 leads to a significant degradation or complete unavailability of affected web applications. Organizations relying on React Router in \u0026quot;Framework Mode\u0026quot; for critical services could experience severe operational disruption. The impact includes financial losses due to service downtime, reputational damage, and potential violation of service level agreements. Affected applications would suffer from resource exhaustion, making them unresponsive to legitimate user requests. While no specific victim counts are provided, React Router is a widely used library, making the potential scope of impact considerable for organizations that have not yet patched.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003enpm/react-router\u003c/code\u003e to version 7.18.0 or later immediately to address CVE-2026-55685.\u003c/li\u003e\n\u003cli\u003eImplement rate-limiting mechanisms at the web application firewall (WAF) or load balancer level to mitigate high-volume requests targeting web application endpoints, specifically focusing on the manifest endpoint referenced in the \u003ccode\u003eAttack Chain\u003c/code\u003e section.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for an unusually high volume of unauthenticated requests to the \u003ccode\u003e/manifest\u003c/code\u003e endpoint or similar paths, as described in the \u003ccode\u003eAttack Chain\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eEnsure server-side monitoring is in place to detect sudden spikes in CPU, memory, or network utilization that could indicate a denial-of-service attack.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T14:09:28Z","date_published":"2026-07-24T14:09:28Z","id":"https://feed.craftedsignal.io/briefs/2026-07-react-router-dos/","summary":"An unauthenticated attacker can exploit CVE-2026-55685 in React Router versions 7.0.0 through 7.17.x, when used in Framework Mode applications, to cause a denial-of-service condition by repeatedly accessing the manifest endpoint, leading to heavy server load and slow response times.","title":"React Router Denial of Service via Inefficient Route Matching (CVE-2026-55685)","url":"https://feed.craftedsignal.io/briefs/2026-07-react-router-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Remix","version":"https://jsonfeed.org/version/1.1"}