shipfeedAI news, curated daily

01:22:16 CET
21 MAY01:22:16shipfeed
pull to refreshlast sync
Just in — 30 new
§ feed · storyline

Protection against React Router vulnerability CVE-2025-31137

Remix 2.16.3 and React Router 7.4.1 release a patch for CVE-2025-31137, a high-severity URL manipulation vulnerability exploitable via the X-Forwarded-Host header.

Apr 17 · · primary fetch1 sourceupdated Apr 17 ·

Security researchers reviewing the Remix web framework have a high-severity vulnerability in React Router that allows URL manipulation through the / header. recently discoveredHostX-Forwarded-Host Our investigation determined that Vercel and our customers are unaffected: A patch has been issued and released in Remix 2.16.3 / React Router 7.4.1. We recommend customers update to the latest version.

Read more about .CVE-2025-31137 Read more We use query parameters as part of the cache key, which protects against cache poisoning driven by the query praram._data The adapter uses similarly to the Express adapter, but it is not possible for an end user to send to a Function hosted on Vercel. @vercel/remixX-Forwarded-HostX-Forwarded-Host

read full article on vercel.com
§ sources1 publication · timeline below
  1. vercel.comProtection against React Router vulnerability CVE-2025-31137primary