Description
A DoS vulnerability exists in the React Router v7 Framework Mode, as well as Remix v2.9.0+ with Single Fetch enabled. In some scenarios the underlying serialization algorithm can become a bottleneck when encoding specific types of data into server responses. Please upgrade to React Router v7.14.0 or later.
Recommendation
Update the turbo-stream package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.0.0
- Patched version(s): 3.0.0
References
Could your website be exposed too?
SmartScanner can check your website for React Router vulnerable to Denial of Service via reflected user input in single-fetch and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig - CVE-2026-25639
- path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters - CVE-2026-4867
- steal vulnerable to Regular Expression Denial of Service via input variable - CVE-2022-37260
- angular vulnerable to regular expression denial of service via the <input type="url"> element - CVE-2023-26118


