A DoS vulnerability exists in the React Router v7 Framework Mode, as well as Remix v2.9.0+ with Single Fetch enabled. In some scenarios the underlying serialization algorithm can become a bottleneck when encoding specific types of data into server responses. Please upgrade to React Router v7.14.0 or later.
> [!NOTE] > This does not impact your React Router application if you are using Declarative Mode () or Data Mode (createBrowserRouter/).
// cvss v3.1 vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Checked 2026-09-26 at 01:03 UTC. The most recent advisory here was published 2026-06-04. Updated continuously from NVD, GHSA, OSV and CNA feeds.