npm package report

Is @remix-run/server-runtime safe?

3 known vulnerabilities, worst severity HIGH.

// reach

7 direct dependencies

3 carry known advisories, worst HIGH

10 packages depend on it

an advisory here reaches each of them

Create a free accountfor every dependency path, dependent and what to upgrade
// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


cvss
0.0
high

severity out of 10

epss
0.00%
medium

chance of exploitation in 30 days, 37th percentile of all CVEs

xyz score
not scored

CyberXYZ composite out of 10

fig. 01 — GHSA-8x6r-g9mw-2r78, the advisory selected below

// 3 advisories

GHSA-8x6r-g9mw-2r78

HIGHCVE-2026-42342

There exists a potential DOS attack vector in React Router Framework Mode applications (as well as Remix v2.10.0 - 2.17.4). Certain requests can be crafted to consume disproportionate resources on the server, resulting in response time degredation and/or service unavailability for end users.

> [!NOTE] > This does not impact your React Router application if you are using Declarative Mode () or Data Mode (createBrowserRouter/).

// cvss v3.1 vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Checked 2026-09-26 at 01:02 UTC. The most recent advisory here was published 2026-06-15. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.