PT-2026-3642 · Unknown · Hotwired Turbo
Publicado
2026-01-20
·
Atualizado
2026-01-21
·
CVE-2025-66803
CVSS v3.1
4.8
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Hotwired Turbo versions prior to 8.0.0
Description
A race condition exists in the turbo-frame element handler. This issue can cause logout operations to fail when delayed frame responses reapply session cookies after a user has logged out. Attackers can exploit this by introducing selective network delays or by leveraging naturally occurring race conditions on shared computers. This allows remote attackers to restore destroyed session cookies, potentially logging a user back in after they have logged out.
Recommendations
Update Hotwired Turbo to version 8.0.0 or later.
Correção
Time Of Check To Time Of Use
Insufficient Session Expiration
Race Condition
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Hotwired Turbo