CVE-2025-43864: React Router allows a DoS via cache poisoning by forcing SPA mode
Summary After some research, it turns out that it is possible to force an application to switch to SPA mode by adding a header to the request. If the application uses SSR and is forced to switch to SPA, this causes an error that completely corrupts the page. If a cache system is in place, this allows the response containing the error to be cached, resulting in a cache poisoning that strongly impacts the availability of the application.
Details The vulnerable header is X-React-Router-SPA-Mode; adding it to a request sent to a page/endpoint using a loader throws an error. Here is the vulnerable code :
<img width="672" alt="Capture d’écran 2025-04-07 à 08 28 20" src="https://github.com/user-attachments/assets/0a0e9c41-70fd-4dba-9061-892dd6797291" />
To use the header, React-router must be used in Framework mode, and for the attack to be possible the target page must use a loader.
Steps to reproduce Versions used for our PoC: - "@react-router/node": "^7.5.0", - "@react-router/serve": "^7.5.0", - "react": "^19.0.0" - "react-dom": "^19.0.0" - "react-router": "^7.5.0"
1. Install React-Router with its default configuration in Framework mode (https://reactrouter.com/start/framework/installation) 2. Add a simple page using a loader (example: routes/ssr)
!image
3. Send a request to the endpoint using the loader (/ssr in our case) adding the following header: X-React-Router-SPA-Mode: yes
Notice the difference between a request with and without the header;
Normal request !Capture d’écran 2025-04-07 à 08 36 27
With the header !Capture d’écran 2025-04-07 à 08 37 01 !image
Impact If a system cache is in place, it is possible to poison the response by completely altering its content (by an error message), strongly impacting its availability, making the latter impractical via a cache-poisoning attack.
Credits - Rachid Allam (zhero;) - Yasser Allam (inzo)
Other sources
React Router is a router for React. Starting in version 7.2.0 and prior to version 7.5.2, it is possible to force an application to switch to SPA mode by adding a header to the request. If the application uses SSR and is forced to switch to SPA, this causes an error that completely corrupts the page. If a cache system is in place, this allows the response containing the error to be cached, resulting in a cache poisoning that strongly impacts the availability of the application. This issue has been patched in version 7.5.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43864?
The severity of CVE-2025-43864 is classified as high due to the potential for application disruption.
How do I fix CVE-2025-43864?
To fix CVE-2025-43864, update your react-router package to version 7.5.2 or higher.
What applications are affected by CVE-2025-43864?
CVE-2025-43864 affects applications using react-router versions below 7.5.2 that utilize server-side rendering.
What happens when CVE-2025-43864 is exploited?
Exploiting CVE-2025-43864 can force an application to switch to single-page application mode, leading to page corruption.
Is CVE-2025-43864 specific to any platforms?
CVE-2025-43864 is specific to applications built with react-router, especially those leveraging server-side rendering.