Resource exhaustion in React Router - CVE-2026-42342
Published: June 19, 2026
React Router
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the __manifest endpoint when handling crafted requests with unbounded path expansion. A remote attacker can send a specially crafted request to cause a denial of service.
Only React Router Framework Mode applications are affected; Declarative Mode and Data Mode are not impacted.