{"id":"CVE-2026-55685","title":"react-router: @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests (CVE-2026-55685)","summary":"A flaw was found in React Router. An unauthenticated attacker can send targeted requests to the manifest endpoint, leading to a denial of service (DoS). This can put a heavy load on the server, significantly slowing down response times and…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":["CWE-770","CWE-400","CWE-407"],"vendor":"Red Hat","product":"Red Hat OpenShift AI 3.4","affected":["exploit_intelligence","network_observability_operator","openshift_lightspeed","openshift_pipelines","ansible_automation_platform 2","build_of_apicurio_registry 3","data_grid 8","enterprise_linux 10","enterprise_linux 9","openshift_ai_rhoai","openshift_container_platform 4","openshift_virtualization 4","quay 3","trusted_profile_analyzer","secrets_management_console_for_red_hat_openshift","openshift_ai 2.25","openshift_ai 3.4"],"patched":["openshift_ai 2.25","openshift_ai 3.4"],"published":"2026-07-27","updated":"2026-09-08","sourceUpdated":"2026-09-08T22:46:27+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55685.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55685.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-55685"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2507833"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-55685"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55685"},{"url":"https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180"},{"url":"https://github.com/remix-run/react-router/commit/09e6020d1950e54f361f7ad00938ecd4dde60929"},{"url":"https://github.com/remix-run/react-router/pull/15186"},{"url":"https://github.com/remix-run/react-router/releases/tag/react-router@7.18.0"},{"url":"https://github.com/remix-run/react-router/security/advisories/GHSA-8x6r-g9mw-2r78"},{"url":"https://github.com/remix-run/react-router/security/advisories/GHSA-chx6-hx7r-mcp5"},{"url":"https://access.redhat.com/errata/RHSA-2026:65126"},{"url":"https://access.redhat.com/errata/RHSA-2026:60520"},{"url":"https://github.com/advisories/GHSA-chx6-hx7r-mcp5"}],"tags":["csaf","vex","red-hat","ghsa","npm"],"epss":0.00403,"epssPercentile":0.34238,"aliases":["GHSA-chx6-hx7r-mcp5"],"ecosystem":"npm","ingestedAt":"2026-07-24T14:29:29.111Z","slug":"CVE-2026-55685","body":"## Overview\n\nA flaw was found in React Router. An unauthenticated attacker can send targeted requests to the manifest endpoint, leading to a denial of service (DoS). This can put a heavy load on the server, significantly slowing down response times and impacting the availability of the application.\n\n## Vendor advisories\n\n- **RHSA-2026:65126** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65126)\n- **RHSA-2026:60520** · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:60520)\n- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Network Observability Operator, OpenShift Lightspeed, OpenShift Pipelines, Red Hat Ansible Automation Platform 2, Red Hat build of Apicurio Registry 3, … · no fix planned: Network Observability Operator, OpenShift Lightspeed, OpenShift Pipelines, Red Hat Ansible Automation Platform 2, … · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55685.json)\n\n**react-router: @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests** — rated Moderate by Red Hat. Released 2026-07-27, updated 2026-09-08.\n\nAffected:\n\n- Exploit Intelligence\n- Network Observability Operator\n- OpenShift Lightspeed\n- OpenShift Pipelines\n- Red Hat Ansible Automation Platform 2\n- Red Hat build of Apicurio Registry 3\n- Red Hat Data Grid 8\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift Virtualization 4\n- Red Hat Quay 3\n- Red Hat Trusted Profile Analyzer\n- Secrets Management Console for Red Hat OpenShift\n\nFixed:\n\n- Red Hat OpenShift AI 2.25\n- Red Hat OpenShift AI 3.4\n\nNo fix planned:\n\n- Network Observability Operator\n- OpenShift Lightspeed\n- OpenShift Pipelines\n- Red Hat Ansible Automation Platform 2\n- Red Hat build of Apicurio Registry 3\n- Red Hat Data Grid 8\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenShift Virtualization 4\n- Red Hat Quay 3\n- Red Hat Trusted Profile Analyzer\n- Secrets Management Console for Red Hat OpenShift\n- Exploit Intelligence\n- Red Hat OpenShift AI (RHOAI)\n\nNot affected:\n\n- Red Hat OpenShift AI 2.25\n- Red Hat OpenShift AI 3.4\n- Cryostat 4\n- Gatekeeper 3\n- Migration Toolkit for Applications 8\n- Migration Toolkit for Containers\n- Migration Toolkit for Virtualization\n- Multicluster Engine for Kubernetes\n- Network Observability Operator\n- Node HealthCheck Operator\n\n## Remediation\n\nFor Red Hat OpenShift AI 2.25.11 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:\n\nhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/ https://access.redhat.com/errata/RHSA-2026:65126\nFor Red Hat OpenShift AI 3.4.4 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:\n\nhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/ https://access.redhat.com/errata/RHSA-2026:60520\n\nWorkarounds / mitigations:\n\n- Upgrade to react-router/@remix-run/server-runtime 7.18.0 or later once the fix is packaged in the affected Red Hat product. Where upgrading isn't immediately possible, rate-limiting or restricting access to the manifest endpoint at a reverse proxy or ingress layer can reduce exposure. Products that do not run React Router in Framework Mode (Declarative Mode or Data Mode only) are not affected regardless of the bundled react-router version.\n\n## Package advisory (CVE-2026-55685)\n\nAffected packages:\n\n- `react-router >= 7.0.0, < 7.18.0`\n\nPatched in:\n\n- `react-router 7.18.0`\n\nSource: https://github.com/advisories/GHSA-chx6-hx7r-mcp5","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":201785,"id":"CVE-2026-55685","ts":1789399723665,"field":"cvss","old":null,"new":"6.5"},{"seq":201784,"id":"CVE-2026-55685","ts":1789399723665,"field":"severity","old":"high","new":"medium"},{"seq":200515,"id":"CVE-2026-55685","ts":1789397364697,"field":"cvss","old":"6.5","new":null},{"seq":200514,"id":"CVE-2026-55685","ts":1789397364697,"field":"severity","old":"medium","new":"high"},{"seq":198432,"id":"CVE-2026-55685","ts":1789391951740,"field":"cvss","old":null,"new":"6.5"},{"seq":198431,"id":"CVE-2026-55685","ts":1789391951740,"field":"severity","old":"high","new":"medium"},{"seq":196225,"id":"CVE-2026-55685","ts":1789383576472,"field":"cvss","old":"6.5","new":null},{"seq":196224,"id":"CVE-2026-55685","ts":1789383576472,"field":"severity","old":"medium","new":"high"},{"seq":195154,"id":"CVE-2026-55685","ts":1789380465584,"field":"cvss","old":null,"new":"6.5"},{"seq":195153,"id":"CVE-2026-55685","ts":1789380465584,"field":"severity","old":"high","new":"medium"},{"seq":193941,"id":"CVE-2026-55685","ts":1789378504892,"field":"cvss","old":"6.5","new":null},{"seq":193940,"id":"CVE-2026-55685","ts":1789378504892,"field":"severity","old":"medium","new":"high"},{"seq":192728,"id":"CVE-2026-55685","ts":1789376396926,"field":"cvss","old":null,"new":"6.5"},{"seq":192727,"id":"CVE-2026-55685","ts":1789376396926,"field":"severity","old":"high","new":"medium"},{"seq":191515,"id":"CVE-2026-55685","ts":1789373410387,"field":"cvss","old":"6.5","new":null},{"seq":191514,"id":"CVE-2026-55685","ts":1789373410387,"field":"severity","old":"medium","new":"high"},{"seq":190300,"id":"CVE-2026-55685","ts":1789369285909,"field":"cvss","old":null,"new":"6.5"},{"seq":190299,"id":"CVE-2026-55685","ts":1789369285909,"field":"severity","old":"high","new":"medium"},{"seq":189087,"id":"CVE-2026-55685","ts":1789368257774,"field":"cvss","old":"6.5","new":null},{"seq":189086,"id":"CVE-2026-55685","ts":1789368257774,"field":"severity","old":"medium","new":"high"},{"seq":187870,"id":"CVE-2026-55685","ts":1789365140375,"field":"cvss","old":null,"new":"6.5"},{"seq":187869,"id":"CVE-2026-55685","ts":1789365140375,"field":"severity","old":"high","new":"medium"},{"seq":186657,"id":"CVE-2026-55685","ts":1789363262229,"field":"cvss","old":"6.5","new":null},{"seq":186656,"id":"CVE-2026-55685","ts":1789363262229,"field":"severity","old":"medium","new":"high"},{"seq":185443,"id":"CVE-2026-55685","ts":1789361088689,"field":"cvss","old":null,"new":"6.5"},{"seq":185442,"id":"CVE-2026-55685","ts":1789361088689,"field":"severity","old":"high","new":"medium"},{"seq":184230,"id":"CVE-2026-55685","ts":1789358146942,"field":"cvss","old":"6.5","new":null},{"seq":184229,"id":"CVE-2026-55685","ts":1789358146942,"field":"severity","old":"medium","new":"high"},{"seq":182481,"id":"CVE-2026-55685","ts":1789354213596,"field":"cvss","old":null,"new":"6.5"},{"seq":182480,"id":"CVE-2026-55685","ts":1789354213596,"field":"severity","old":"high","new":"medium"},{"seq":181274,"id":"CVE-2026-55685","ts":1789353110988,"field":"cvss","old":"6.5","new":null},{"seq":181273,"id":"CVE-2026-55685","ts":1789353110988,"field":"severity","old":"medium","new":"high"},{"seq":180067,"id":"CVE-2026-55685","ts":1789350158626,"field":"cvss","old":null,"new":"6.5"},{"seq":180066,"id":"CVE-2026-55685","ts":1789350158626,"field":"severity","old":"high","new":"medium"},{"seq":178860,"id":"CVE-2026-55685","ts":1789348090492,"field":"cvss","old":"6.5","new":null},{"seq":178859,"id":"CVE-2026-55685","ts":1789348090492,"field":"severity","old":"medium","new":"high"},{"seq":177653,"id":"CVE-2026-55685","ts":1789346270175,"field":"cvss","old":null,"new":"6.5"},{"seq":177652,"id":"CVE-2026-55685","ts":1789346270175,"field":"severity","old":"high","new":"medium"},{"seq":176446,"id":"CVE-2026-55685","ts":1789343008535,"field":"cvss","old":"6.5","new":null},{"seq":176445,"id":"CVE-2026-55685","ts":1789343008535,"field":"severity","old":"medium","new":"high"},{"seq":174563,"id":"CVE-2026-55685","ts":1789334757813,"field":"cvss","old":null,"new":"6.5"},{"seq":174562,"id":"CVE-2026-55685","ts":1789334757813,"field":"severity","old":"high","new":"medium"},{"seq":173358,"id":"CVE-2026-55685","ts":1789333483757,"field":"cvss","old":"6.5","new":null},{"seq":173357,"id":"CVE-2026-55685","ts":1789333483757,"field":"severity","old":"medium","new":"high"},{"seq":172172,"id":"CVE-2026-55685","ts":1789331000801,"field":"cvss","old":null,"new":"6.5"},{"seq":172171,"id":"CVE-2026-55685","ts":1789331000801,"field":"severity","old":"high","new":"medium"},{"seq":170986,"id":"CVE-2026-55685","ts":1789328605780,"field":"cvss","old":"6.5","new":null},{"seq":170985,"id":"CVE-2026-55685","ts":1789328605780,"field":"severity","old":"medium","new":"high"},{"seq":169781,"id":"CVE-2026-55685","ts":1789327044302,"field":"cvss","old":null,"new":"6.5"},{"seq":169780,"id":"CVE-2026-55685","ts":1789327044302,"field":"severity","old":"high","new":"medium"}]}