Input validation error in Remix - CVE-2025-31137
Published: April 1, 2025 / Updated: June 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to spoof the URL used in an incoming request.
The vulnerability exists due to improper input validation in the Express adapter request handler when processing Host or X-Forwarded-Host headers. A remote attacker can send a specially crafted Host or X-Forwarded-Host header containing a URL pathname in the port section to spoof the URL used in an incoming request.
Affected software
React Router
How to mitigate CVE-2025-31137
React Router - update to 7.4.1