CVE-2025-31137 Details
Description
React Router is a multi-strategy router for React bridging the gap from React 18 to React 19. There is a vulnerability in Remix/React Router that affects all Remix 2 and React Router 7 consumers using the Express adapter. Basically, this vulnerability allows anyone to spoof the URL used in an incoming Request by putting a URL pathname in the port section of a URL that is part of a Host or X-Forwarded-Host header sent to a Remix/React Router request handler. This issue has been patched and released in Remix 2.16.3 and React Router 7.4.1.
A vulnerability exists in React Router versions 7.0.0 through 7.4.0 and in Remix versions 2.11.1 through 2.16.2, specifically when using the Express adapter. This vulnerability allows for URL spoofing in incoming requests by manipulating the port section of a URL within the Host or X-Forwarded-Host headers. The spoofed URL can then be used to deceive the request handler about the actual request origin.
Users can upgrade to React Router version 7.4.1 or Remix version 2.16.3 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 1, 2025CISA-ADP
Assessed Apr 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/remix-run/react-router/security/advisories/GHSA-4q56-crqp-v477 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| @remix-run/express | All versions |
CPE
Remediation
| |
| @react-router/express | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 1, 2025 | New CVE Received | [email protected] |
Volerion