← Vulnerability feed

Vulnerability record · CVE-2026-42342 · published 2 June 2026

CVE-2026-42342: Shopify react-router uncontrolled resource consumption vulnerability

Shopify · React Router

React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can consume disproportionate server resources via unbounded path expansion in the __manifest endpoint, resulting in response time degradation and/or service unavailability for end users. This affects React Router Framework Mode applications as well as Remix applications. This does not impact applications using Declarative Mode (`<BrowserRouter>`) or Data Mode (`createBrowserRouter/<RouterProvider>`). This is patched in react-router version 7.15.0 and @remix-run/server-runtime version 2.17.5.

7.5 CVSS 3.1 High EPSS 0.46% · top 62.7% CWE-400 · Uncontrolled resource consumption
7.5CVSS 3.1 base score
0.46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
21 Jul 2026Last modified by NVD

Description

React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can consume disproportionate server resources via unbounded path expansion in the __manifest endpoint, resulting in response time degradation and/or service unavailability for end users. This affects React Router Framework Mode applications as well as Remix applications. This does not impact applications using Declarative Mode (`<BrowserRouter>`) or Data Mode (`createBrowserRouter/<RouterProvider>`). This is patched in react-router version 7.15.0 and @remix-run/server-runtime version 2.17.5.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-42342 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2026-55685Shopify react-router uncontrolled resource consumption vulnerabilityReact Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests t…EPSS 0.71%8.2CVE-2026-21884Shopify react-router cross-site scripting vulnerabilityReact Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, a XSS vulnerability exists in…EPSS 0.54%8.1CVE-2026-42211Shopify react-router deserialization of untrusted data vulnerabilityReact Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unaut…EPSS 0.62%7.6CVE-2025-59057Shopify react-router cross-site scripting vulnerabilityReact Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 through 7.8.2, a XSS vulnerab…EPSS 0.51%7.5CVE-2026-34077Shopify react-router allocation without limits vulnerabilityReact Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is…EPSS 0.45%6.9CVE-2026-53668Shopify react-router cross-site scripting vulnerabilityReact Router is a router for React. In versions 6.30.2 through 6.30.4 and 7.9.6 through 7.12.0, applications that allow open redirects are vulnerable…EPSS 0.34%6.6CVE-2026-40181Shopify react-router open redirect vulnerabilityReact Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigg…EPSS 0.26%6.5CVE-2026-22030Shopify react-router origin validation error vulnerabilityReact Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, React Router (or Rem…EPSS 0.19%

Source: NIST National Vulnerability Database (record CVE-2026-42342), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.