Resource exhaustion in React Router - CVE-2026-42342
Published: June 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the __manifest endpoint when handling crafted requests with unbounded path expansion. A remote attacker can send a specially crafted request to cause a denial of service.
Only React Router Framework Mode applications are affected; Declarative Mode and Data Mode are not impacted.
Affected software
server-runtime
Jira Service Management Data Center
Jira Software Data Center
IBM SPSS Collaboration and Deployment Services
How to mitigate CVE-2026-42342
server-runtime - update to 2.17.5
Jira Service Management Data Center - update to 10.3.14
Jira Software Data Center - update to 10.3.14
IBM SPSS Collaboration and Deployment Services - update to 9.0.0.0.0 IF13