Latest
Alerts
Security
DevOps
Cloud
AI
Self-hosted
Linux
Networking
Search
⌘K
FR
live
CVE-2026-48710 · Kludex Starlette
CVE-2026-49869 · Kestra Kestra OSS
CVE-2026-59822 · BerriAI LiteLLM · CVSS 8.2
CVE-2026-82329 · JFrog Artifactory
home
alerts
Shopify
vendor
Shopify
1
vulnerability tracked
27 July 2026
latest publication
cve
Vulnerability watch
id
vulnerability
severity
published
CVE-2026-55685
React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times. This issue is a follow up to CVE-2026-42342, and does not does not impact React Router applications using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>). This issue has been fixed in version 7.18.0.
Shopify React-router
High
CVSS 8.7
27/07
← Back to the watch
esc
Type at least two characters.
↑
↓
navigate
↵
open
esc
dismiss