SB2025082135 - Improper handling of exceptional conditions in React Router
Published: August 21, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper handling of exceptional conditions (CVE-ID: CVE-2025-43864)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper handling of errors. A remote attacker can send specially crafted input and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://github.com/remix-run/react-router/blob/e6c53a0130559b4a9bd47f9cf76ea5b08a69868a/packages/react-router/lib/server-runtime/server.ts#L407
- https://github.com/remix-run/react-router/commit/c84302972a152d851cf5dd859ff332b354b70111
- https://github.com/remix-run/react-router/security/advisories/GHSA-f46r-rw29-r322