AI description
CVE-2025-43864 affects React Router, a routing library for React applications. Specifically, versions 7.2.0 up to 7.5.1 are vulnerable. It is possible to force an application to switch to SPA (Single Page Application) mode by adding a specific header (`X-React-Router-SPA-Mode`) to the request. If an application using server-side rendering (SSR) is forced into SPA mode, it can cause an error that corrupts the page. Furthermore, if a caching system is in place, this error response can be cached, leading to a cache poisoning issue that impacts the application's availability. The vulnerability is fixed in version 7.5.2 of React Router.
- Description
- React Router is a router for React. Starting in version 7.2.0 and prior to version 7.5.2, it is possible to force an application to switch to SPA mode by adding a header to the request. If the application uses SSR and is forced to switch to SPA, this causes an error that completely corrupts the page. If a cache system is in place, this allows the response containing the error to be cached, resulting in a cache poisoning that strongly impacts the availability of the application. This issue has been patched in version 7.5.2.
- Source
- security-advisories@github.com
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
- security-advisories@github.com
- CWE-755
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
36
π¨ CVE-2025-43864 π΄ HIGH (7.5) π’ remix-run - react-router ποΈ >= 7.2.0, < 7.5.2 π https://t.co/cUyhKOe65X π https://t.co/7QnIjVRwSH π https://t.co/rB1xUD1ck8 #CyberCron #VulnAlert #InfoSec https://t.co/uTf9qE9Mow
@cybercronai
25 Apr 2025
22 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-43864 React Router is a router for React. Starting in version 7.2.0 and prior to version 7.5.2, it is possible to force an application to switch to SPA mode by adding a hea⦠https://t.co/fo5VJpIVQU
@CVEnew
25 Apr 2025
303 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
another research effort with @inzo____ led to the discovery of two new vulnerabilities in React Router (14M+ downloads/week), resulting in: - CVE-2025-43865 (High-8.2) - CVE-2025-43864 (High-7.5) https://t.co/ooTe702fat
@zhero___
24 Apr 2025
21739 Impressions
46 Retweets
407 Likes
160 Bookmarks
19 Replies
3 Quotes