Skip to content
VulniPulse
Advisory severityMedium6.5Red Hat Linux

Medium [CVE-2026-55685] @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests

This medium-severity Red Hat Linux advisory covers CVE-2026-55685 affecting Red Hat OpenShift AI 3.4, Exploit Intelligence, Network Observability Operator.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-55685 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times.

This issue has been fixed in version 7.18.0. An unauthenticated attacker can send targeted requests to the manifest endpoint, leading to a denial of service (DoS).

This can put a heavy load on the server, significantly slowing down response times and impacting the availability of the application. Repeated, targeted requests to this endpoint place heavy load on the server and can degrade or deny service for other users.

Applications using Declarative Mode () or Data Mode (createBrowserRouter/) do not run this server-side code path and are not affected. This mirrors the same re-scoring applied to the predecessor flaw, CVE-2026-42342, for the same endpoint family.

Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770.

Affected products named by the advisory: Red Hat OpenShift AI 3.4; Exploit Intelligence; Network Observability Operator; OpenShift Lightspeed; and 13 more.

Affected versions
  • 7.0.0
  • 7.17.0

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Fixed versions
  • 7.18.0
  • rhoai/odh-dashboard-rhel9:1787347991
  • rhoai/odh-mod-arch-automl-rhel9:1787250508
  • rhoai/odh-mod-arch-autorag-rhel9:1787251550
  • rhoai/odh-mod-arch-gen-ai-rhel9:1786611759
  • rhoai/odh-mod-arch-maas-rhel9:1787251250
  • rhoai/odh-mod-arch-mlflow-rhel9:1786612219
  • rhoai/odh-mod-arch-model-registry-rhel9:1787250617
  • RHSA-2026:60520

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Upgrade to react-router/@remix-run/server-runtime 7.18.0 or later once the fix is packaged in the affected Red Hat product. Where upgrading isn't immediately possible, rate-limiting or restricting access to the manifest endpoint at a reverse proxy or ingress layer can reduce exposure. Products that do not run React Router in Framework Mode (Declarative Mode or Data Mode only) are not affected regardless of the bundled react-router version.

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.