Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
Vulnerability Description
React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times. This issue is a follow up to CVE-2026-42342, and does not does not impact React Router applications using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>). This issue has been fixed in version 7.18.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
remix-run react-router 资源管理错误漏洞
Vulnerability Description
remix-run react-router是remix-run的路由管理库。 remix-run react-router 7.0.0版本至7.17.0版本存在资源管理错误漏洞,该漏洞源于manifest端点可以被未经身份验证的定向请求访问,导致服务器负载增加和响应时间变慢。
CVSS Information
N/A
Vulnerability Type
N/A