Resource exhaustion in turbo-stream - CVE-2026-34077
Published: June 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the single-fetch serialization algorithm when encoding specific types of data into server responses. A remote attacker can supply crafted input that is reflected into a server response to cause a denial of service.
Only React Router v7 framework mode and Remix with single fetch enabled are vulnerable.
Affected software
React Router
Jira Service Management Data Center
Jira Software Data Center
IBM SPSS Collaboration and Deployment Services
JBoss Data Grid
How to mitigate CVE-2026-34077
React Router - update to 7.14.0
Jira Service Management Data Center - update to 10.3.14
Jira Software Data Center - update to 10.3.14
JBoss Data Grid - update to 8.6.2
IBM SPSS Collaboration and Deployment Services - update to 9.0.0.0.0 IF13
External References
Related Security Bulletins
- Resource exhaustion in turbo-stream
- Denial of service in React Router
- Multiple vulnerabilities in Jira Service Management Data Center
- Multiple vulnerabilities in Jira Software Data Center
- Multiple vulnerabilities in IBM SPSS Collaboration and Deployment Services
- Multiple vulnerabilities in JBoss Data Grid 8.6