Input validation error in Remix - CVE-2025-31137
Published: April 1, 2025 / Updated: June 19, 2026
Remix
Detailed vulnerability description
The vulnerability allows a remote attacker to spoof the URL used in an incoming request.
The vulnerability exists due to improper input validation in the Express adapter request handler when processing Host or X-Forwarded-Host headers. A remote attacker can send a specially crafted Host or X-Forwarded-Host header containing a URL pathname in the port section to spoof the URL used in an incoming request.