Description
A race condition in Turbo Frames allows delayed HTTP responses to restore stale session cookies after session-modifying operations.
Recommendation
Update the @hotwired/turbo package to the latest compatible version. Followings are version details:
- Affected version(s): <= 8.0.20
- Patched version(s): 8.0.21
References
Could your website be exposed too?
SmartScanner can check your website for Turbo Frame responses can restore stale session cookies and gives you actionable findings to investigate.
Start a free scanRelated Issues
- authkit-nextjs may let session cookies be cached in CDNs - CVE-2025-64762
- Suspended Directus user can continue to use session token to access API - CVE-2025-30351
- Strapi is vulnerable to Insufficient Session Expiration - CVE-2025-3930
- React Router has Path Traversal in File Session Storage - CVE-2025-61686
You might also like:
See something that needs correcting? Let us knowUpdated January 21, 2026


