漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
Vulnerability Description
React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the server and slow down response times. This issue is a follow up to CVE-2026-42342, and does not does not impact React Router applications using Declarative Mode (<BrowserRouter>) or Data Mode (createBrowserRouter/<RouterProvider>). This issue has been fixed in version 7.18.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Vulnerability Title
remix-run react-router 资源管理错误漏洞
Vulnerability Description
remix-run react-router是remix-run的路由管理库。 remix-run react-router 7.0.0版本至7.17.0版本存在资源管理错误漏洞,该漏洞源于manifest端点可以被未经身份验证的定向请求访问,导致服务器负载增加和响应时间变慢。
CVSS Information
N/A
Vulnerability Type
N/A