Resource exhaustion in React Router - CVE-2026-42342
Published: June 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the __manifest endpoint when handling crafted requests with unbounded path expansion. A remote attacker can send a specially crafted request to cause a denial of service.
Only React Router Framework Mode applications are affected; Declarative Mode and Data Mode are not impacted.
Affected software
server-runtime
Jira Service Management Data Center
Jira Software Data Center
IBM SPSS Collaboration and Deployment Services
MongoDB Enterprise Advanced with IBM
JBoss Data Grid
How to mitigate CVE-2026-42342
server-runtime - update to 2.17.5
Jira Service Management Data Center - update to 10.3.14
Jira Software Data Center - update to 10.3.14
MongoDB Enterprise Advanced with IBM - update to 1.16.2
JBoss Data Grid - update to 8.6.2
IBM SPSS Collaboration and Deployment Services - update to 9.0.0.0.0 IF13
External References
Related Security Bulletins
- Resource exhaustion in React Router
- Multiple vulnerabilities in server-runtime
- Multiple vulnerabilities in Jira Service Management Data Center
- Multiple vulnerabilities in Jira Software Data Center
- Multiple vulnerabilities in IBM SPSS Collaboration and Deployment Services
- MongoDB Enterprise Advanced with IBM update for React Router
- Multiple vulnerabilities in JBoss Data Grid 8.6