Resource exhaustion in turbo-stream - CVE-2026-34077
Published: June 19, 2026
turbo-stream
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the single-fetch serialization algorithm when encoding specific types of data into server responses. A remote attacker can supply crafted input that is reflected into a server response to cause a denial of service.
Only React Router v7 framework mode and Remix with single fetch enabled are vulnerable.