CVE-2026-55685

React Router: Unauthenticated Denial of Service via Inefficient Route Matching

React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times. This issue is a follow up to CVE-2026-42342, and does not does not impact React Router applications using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>). This issue has been fixed in version 7.18.0.


We have discovered 371 live websites that are affected by CVE-2026-55685.

Run a Free Instant Scan




Affected Software

Product  React Router DOM
Category JavaScript Libraries
Vulnerable Domains371 live websites (40% of React Router DOM install base)
Vulnerable Versions
  • from 7 through 7.18
Vulnerable Versions Count23 versions ( 40% of all versions)


Common Weakness Enumeration

CWE-400 Uncontrolled Resource Consumption



Details

  • Published - Jul 27, 2026
  • Updated - Jul 28, 2026

Website Distribution by Country

Number of websites using CVE-2026-55685
United States55 websites



New Zealand225 websites
Germany37 websites
Russia8 websites
France6 websites
Australia4 websites
Cyprus4 websites
Japan4 websites
Belgium2 websites
Brazil2 websites

Website Distribution by TLD

Number of websites using CVE-2026-55685
.com83 websites
.ru8 websites
.net8 websites
.org4 websites
.be2 websites
.com.au2 websites
.com.br2 websites
.de2 websites
.ca1 websites
.co1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-55685

Top websites that are affected by CVE-2026-55685. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.org United States***,***
*****.run United States***,***
************.com Canada***,***
***********.net United States*,***,***
****.***.nz New Zealand*,***,***
*************.**.nz New Zealand*,***,***
**********.com United States*,***,***
*********.**.nz Australia*,***,***
**************.**.nz New Zealand*,***,***
**********.**.nz New Zealand*,***,***
See full domain list

FAQ

CVE-2026-55685 is Uncontrolled Resource Consumption in React Router DOM
A total of 371 websites have been identified as vulnerable to CVE-2026-55685, based on global website indexing conducted by WebTechSurvey.
The React Router DOM is affected by the CVE-2026-55685 vulnerability.
React Router DOM versions up to 7.18 are vulnerable to CVE-2026-55685.
CVE-2026-55685 is resolved in version 7.18 of React Router DOM.