---
id: CVE-2026-55685
title: >-
  react-router: @remix-run/server-runtime: React Router: Denial of Service via
  unauthenticated manifest endpoint requests (CVE-2026-55685)
summary: >-
  A flaw was found in React Router. An unauthenticated attacker can send
  targeted requests to the manifest endpoint, leading to a denial of service
  (DoS). This can put a heavy load on the server, significantly slowing down
  response times and…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe:
  - CWE-770
  - CWE-400
  - CWE-407
vendor: Red Hat
product: Red Hat OpenShift AI 3.4
affected:
  - exploit_intelligence
  - network_observability_operator
  - openshift_lightspeed
  - openshift_pipelines
  - ansible_automation_platform 2
  - build_of_apicurio_registry 3
  - data_grid 8
  - enterprise_linux 10
  - enterprise_linux 9
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - openshift_virtualization 4
  - quay 3
  - trusted_profile_analyzer
  - secrets_management_console_for_red_hat_openshift
  - openshift_ai 2.25
  - openshift_ai 3.4
patched:
  - openshift_ai 2.25
  - openshift_ai 3.4
published: '2026-07-27'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T22:46:27+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55685.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55685.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-55685'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2507833'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-55685'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55685'
  - url: 'https://github.com/remix-run/react-router/blob/main/CHANGELOG.md#v7180'
  - url: >-
      https://github.com/remix-run/react-router/commit/09e6020d1950e54f361f7ad00938ecd4dde60929
  - url: 'https://github.com/remix-run/react-router/pull/15186'
  - url: 'https://github.com/remix-run/react-router/releases/tag/react-router@7.18.0'
  - url: >-
      https://github.com/remix-run/react-router/security/advisories/GHSA-8x6r-g9mw-2r78
  - url: >-
      https://github.com/remix-run/react-router/security/advisories/GHSA-chx6-hx7r-mcp5
  - url: 'https://access.redhat.com/errata/RHSA-2026:65126'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60520'
  - url: 'https://github.com/advisories/GHSA-chx6-hx7r-mcp5'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - npm
epss: 0.00708
epssPercentile: 0.5141
aliases:
  - GHSA-chx6-hx7r-mcp5
ecosystem: npm
ingestedAt: '2026-07-24T14:29:29.111Z'
---

## Overview

A flaw was found in React Router. An unauthenticated attacker can send targeted requests to the manifest endpoint, leading to a denial of service (DoS). This can put a heavy load on the server, significantly slowing down response times and impacting the availability of the application.

## Vendor advisories

- **RHSA-2026:65126** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65126)
- **RHSA-2026:60520** · Red Hat · fixed in: Red Hat OpenShift AI 3.4 · released 2026-08-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:60520)
- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Network Observability Operator, OpenShift Lightspeed, OpenShift Pipelines, Red Hat Ansible Automation Platform 2, Red Hat build of Apicurio Registry 3, … · no fix planned: Network Observability Operator, OpenShift Lightspeed, OpenShift Pipelines, Red Hat Ansible Automation Platform 2, … · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55685.json)

**react-router: @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests** — rated Moderate by Red Hat. Released 2026-07-27, updated 2026-09-08.

Affected:

- Exploit Intelligence
- Network Observability Operator
- OpenShift Lightspeed
- OpenShift Pipelines
- Red Hat Ansible Automation Platform 2
- Red Hat build of Apicurio Registry 3
- Red Hat Data Grid 8
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift Virtualization 4
- Red Hat Quay 3
- Red Hat Trusted Profile Analyzer
- Secrets Management Console for Red Hat OpenShift

Fixed:

- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.4

No fix planned:

- Network Observability Operator
- OpenShift Lightspeed
- OpenShift Pipelines
- Red Hat Ansible Automation Platform 2
- Red Hat build of Apicurio Registry 3
- Red Hat Data Grid 8
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat OpenShift Container Platform 4
- Red Hat OpenShift Virtualization 4
- Red Hat Quay 3
- Red Hat Trusted Profile Analyzer
- Secrets Management Console for Red Hat OpenShift
- Exploit Intelligence
- Red Hat OpenShift AI (RHOAI)

Not affected:

- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.4
- Cryostat 4
- Gatekeeper 3
- Migration Toolkit for Applications 8
- Migration Toolkit for Containers
- Migration Toolkit for Virtualization
- Multicluster Engine for Kubernetes
- Network Observability Operator
- Node HealthCheck Operator

## Remediation

For Red Hat OpenShift AI 2.25.11 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:

https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ https://access.redhat.com/errata/RHSA-2026:65126
For Red Hat OpenShift AI 3.4.4 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:

https://docs.redhat.com/en/documentation/red_hat_openshift_ai/ https://access.redhat.com/errata/RHSA-2026:60520

Workarounds / mitigations:

- Upgrade to react-router/@remix-run/server-runtime 7.18.0 or later once the fix is packaged in the affected Red Hat product. Where upgrading isn't immediately possible, rate-limiting or restricting access to the manifest endpoint at a reverse proxy or ingress layer can reduce exposure. Products that do not run React Router in Framework Mode (Declarative Mode or Data Mode only) are not affected regardless of the bundled react-router version.

## Package advisory (CVE-2026-55685)

Affected packages:

- `react-router >= 7.0.0, < 7.18.0`

Patched in:

- `react-router 7.18.0`

Source: https://github.com/advisories/GHSA-chx6-hx7r-mcp5
