React Router vulnerable to Denial of Service via reflected user input in single-fetch
- Severity:
- High
Description
A DoS vulnerability exists in the React Router v7 Framework Mode, as well as Remix v2.9.0+ with Single Fetch enabled. In some scenarios the underlying serialization algorithm can become a bottleneck when encoding specific types of data into server responses. Please upgrade to React Router v7.14.0 or later.
Recommendation
Update the turbo-stream package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.0.0
- Patched version(s): 3.0.0
References
Related Issues
- Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig - CVE-2026-25639
- path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters - CVE-2026-4867
- steal vulnerable to Regular Expression Denial of Service via input variable - CVE-2022-37260
- angular vulnerable to regular expression denial of service via the <input type="url"> element - CVE-2023-26118
You might also like:
- Tags:
- npm
- turbo-stream
Anything's wrong? Let us know Last updated on June 04, 2026


