Resource exhaustion in React Router - CVE-2026-55685
Published: July 22, 2026
Vulnerability identifier: #VU139178
CSH Severity: Low
CVSS v4: 5.4 [CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55685
CWE-ID: CWE-400
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the __manifest endpoint when handling targeted unauthenticated requests. A remote user can send targeted requests to cause a denial of service.
Only Framework Mode applications are vulnerable.
Affected software
React Router
IBM SPSS Collaboration and Deployment Services
Jira Service Management Data Center
Jira Software Data Center
IBM SPSS Collaboration and Deployment Services
Jira Service Management Data Center
Jira Software Data Center
How to mitigate CVE-2026-55685
Install security update from vendor's website.
React Router - update to 7.18.0
Jira Service Management Data Center - addressed in versions 10.3.14, 11.2.0
Jira Software Data Center - update to 10.3.14
Jira Service Management Data Center - addressed in versions 10.3.14, 11.2.0
Jira Software Data Center - update to 10.3.14