Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2026-55685

CVE-2026-55685: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityMedium6.5

    Medium [CVE-2026-55685] @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests

    CVE-2026-55685Source published Source updated

    React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times. This issue has been fixed in version 7.18.0. An unauthenticated attacker can send targeted requests to the manifest endpoint, leading to a denial of service (DoS). This can put a heavy load on the server, significantly slowing down response times and impacting the availability of the application. Repeated, targeted requests to this endpoint place heavy load on the server and can degrade or deny service for other users. Applications using Declarative Mode () or Data Mode (createBrowserRouter/) do not run this server-side code path and are not affected. This mirrors the same…

    Affected products in this advisory
    • Red Hat OpenShift AI 3.4
    • Exploit Intelligence
    • Network Observability Operator
    • OpenShift Lightspeed

    13 more entries in the full advisory.

    Source-reported affected versions
    • 7.0.0
    • 7.17.0
    Source-reported fixed versions
    • 7.18.0
    • rhoai/odh-dashboard-rhel9:1787347991
    • rhoai/odh-mod-arch-automl-rhel9:1787250508
    • rhoai/odh-mod-arch-autorag-rhel9:1787251550

    5 more entries in the full advisory.

    Mitigation guidance
    • Upgrade to react-router/@remix-run/server-runtime 7.18.0 or later once the fix is packaged in the affected Red Hat product. Where upgrading isn't immediately possible, rate-limiting or restricting access to the manifest endpoint at a reverse proxy or ingress layer can reduce exposure. Products that do not run React Router in Framework Mode (Declarative Mode or Data Mode only) are not affected regardless of the bundled react-router version.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery