PT-2026-3642 · Unknown · Hotwired Turbo

Publicado

2026-01-20

·

Atualizado

2026-01-21

·

CVE-2025-66803

CVSS v3.1

4.8

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Hotwired Turbo versions prior to 8.0.0
Description A race condition exists in the turbo-frame element handler. This issue can cause logout operations to fail when delayed frame responses reapply session cookies after a user has logged out. Attackers can exploit this by introducing selective network delays or by leveraging naturally occurring race conditions on shared computers. This allows remote attackers to restore destroyed session cookies, potentially logging a user back in after they have logged out.
Recommendations Update Hotwired Turbo to version 8.0.0 or later.

Correção

Time Of Check To Time Of Use

Insufficient Session Expiration

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-66803
GHSA-QPPM-G56G-FPVP

Produtos afetados

Hotwired Turbo