Medium [CVE-2026-55685] @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests
This medium-severity Red Hat Linux advisory covers CVE-2026-55685 affecting Red Hat OpenShift AI 3.4, Exploit Intelligence, Network Observability Operator.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times.
This issue has been fixed in version 7.18.0. An unauthenticated attacker can send targeted requests to the manifest endpoint, leading to a denial of service (DoS).
This can put a heavy load on the server, significantly slowing down response times and impacting the availability of the application. Repeated, targeted requests to this endpoint place heavy load on the server and can degrade or deny service for other users.
Applications using Declarative Mode () or Data Mode (createBrowserRouter/) do not run this server-side code path and are not affected. This mirrors the same re-scoring applied to the predecessor flaw, CVE-2026-42342, for the same endpoint family.
Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770.
Affected products named by the advisory: Red Hat OpenShift AI 3.4; Exploit Intelligence; Network Observability Operator; OpenShift Lightspeed; and 13 more.
- 7.0.0
- 7.17.0
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
- 7.18.0
- rhoai/odh-dashboard-rhel9:1787347991
- rhoai/odh-mod-arch-automl-rhel9:1787250508
- rhoai/odh-mod-arch-autorag-rhel9:1787251550
- rhoai/odh-mod-arch-gen-ai-rhel9:1786611759
- rhoai/odh-mod-arch-maas-rhel9:1787251250
- rhoai/odh-mod-arch-mlflow-rhel9:1786612219
- rhoai/odh-mod-arch-model-registry-rhel9:1787250617
- RHSA-2026:60520
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Mitigation checklist
- Upgrade to react-router/@remix-run/server-runtime 7.18.0 or later once the fix is packaged in the affected Red Hat product. Where upgrading isn't immediately possible, rate-limiting or restricting access to the manifest endpoint at a reverse proxy or ingress layer can reduce exposure. Products that do not run React Router in Framework Mode (Declarative Mode or Data Mode only) are not affected regardless of the bundled react-router version.
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.