@react-router/express@7.1.1-pre.0 vulnerabilities

Express server request handler for React Router

  • latest version

    7.5.0

  • latest non vulnerable version

  • first published

    11 months ago

  • latest version published

    19 hours ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @react-router/express package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    HTTP Request Smuggling

    @react-router/express is an Express server request handler for React Router

    Affected versions of this package are vulnerable to HTTP Request Smuggling via Host or X-Forwarded-Host headers. An attacker can spoof the URL used in an incoming request's Host or X-Forwarded-Host header by passing in a URL pathname as the port of a URL.

    How to fix HTTP Request Smuggling?

    Upgrade @react-router/express to version 7.4.1-pre.0 or higher.

    >=7.0.0 <7.4.1-pre.0