Resource exhaustion in turbo-stream - CVE-2026-34077
Published: June 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the single-fetch serialization algorithm when encoding specific types of data into server responses. A remote attacker can supply crafted input that is reflected into a server response to cause a denial of service.
Only React Router v7 framework mode and Remix with single fetch enabled are vulnerable.
Affected software
React Router
Jira Service Management Data Center
Jira Software Data Center
IBM SPSS Collaboration and Deployment Services
How to mitigate CVE-2026-34077
React Router - update to 7.14.0
Jira Service Management Data Center - update to 10.3.14
Jira Software Data Center - update to 10.3.14
IBM SPSS Collaboration and Deployment Services - update to 9.0.0.0.0 IF13