Resource exhaustion in React Router - CVE-2026-55685

 

Resource exhaustion in React Router - CVE-2026-55685

Published: July 22, 2026


Vulnerability identifier: #VU139178
CSH Severity: Low
CVSS v4: 5.4 [CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55685
CWE-ID: CWE-400
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the __manifest endpoint when handling targeted unauthenticated requests. A remote user can send targeted requests to cause a denial of service.

Only Framework Mode applications are vulnerable.


Affected software

React Router
IBM SPSS Collaboration and Deployment Services
Jira Service Management Data Center
Jira Software Data Center

How to mitigate CVE-2026-55685

Install security update from vendor's website.

React Router - update to 7.18.0
Jira Service Management Data Center - addressed in versions 10.3.14, 11.2.0
Jira Software Data Center - update to 10.3.14

External References

Related Security Bulletins