Vulnerabilities/

React Router vulnerable to Denial of Service via reflected user input in single-fetch

Severity:
High

Description

A DoS vulnerability exists in the React Router v7 Framework Mode, as well as Remix v2.9.0+ with Single Fetch enabled. In some scenarios the underlying serialization algorithm can become a bottleneck when encoding specific types of data into server responses. Please upgrade to React Router v7.14.0 or later.

Recommendation

Update the turbo-stream package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
turbo-stream
Anything's wrong? Let us know Last updated on June 04, 2026