Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8x6r-g9mw-2r78 | React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint |
Fri, 26 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 04 Jun 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shopify
Shopify react-router Shopify remix-run\/server-runtime |
|
| CPEs | cpe:2.3:a:shopify:react-router:*:*:*:*:*:node.js:*:* cpe:2.3:a:shopify:remix-run\/server-runtime:*:*:*:*:*:node.js:*:* |
|
| Vendors & Products |
Shopify
Shopify react-router Shopify remix-run\/server-runtime |
Wed, 03 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Jun 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Remix-run
Remix-run react-router Remix-run server-runtime |
|
| Vendors & Products |
Remix-run
Remix-run react-router Remix-run server-runtime |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can consume disproportionate server resources via unbounded path expansion in the __manifest endpoint, resulting in response time degradation and/or service unavailability for end users. This affects React Router Framework Mode applications as well as Remix applications. This does not impact applications using Declarative Mode (`<BrowserRouter>`) or Data Mode (`createBrowserRouter/<RouterProvider>`). This is patched in react-router version 7.15.0 and @remix-run/server-runtime version 2.17.5. | |
| Title | React Router vulnerable to DoS via unbounded path expansion in __manifest endpoint | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-03T13:52:43.400Z
Reserved: 2026-04-26T13:26:14.514Z
Link: CVE-2026-42342
Updated: 2026-06-03T13:52:37.648Z
Status : Analyzed
Published: 2026-06-02T20:16:36.693
Modified: 2026-06-04T19:00:32.600
Link: CVE-2026-42342
OpenCVE Enrichment
Updated: 2026-06-26T02:15:15Z
Github GHSA