Description
A race condition in Turbo Frames allows delayed HTTP responses to restore stale session cookies after session-modifying operations.
Recommendation
Update the @hotwired/turbo package to the latest compatible version. Followings are version details:
- Affected version(s): <= 8.0.20
- Patched version(s): 8.0.21
References
- GHSA-qppm-g56g-fpvp
- turbo.hotwired.dev
- CVE-2025-66803
- CWE-362
- CWE-367
- CWE-613
- CAPEC-310
- OWASP 2021-A6
- OWASP 2021-A7
Related Issues
- authkit-nextjs may let session cookies be cached in CDNs - CVE-2025-64762
- Suspended Directus user can continue to use session token to access API - CVE-2025-30351
- Strapi is vulnerable to Insufficient Session Expiration - CVE-2025-3930
- React Router has Path Traversal in File Session Storage - CVE-2025-61686
You might also like:
- Tags:
- npm
- @hotwired/turbo
Anything's wrong? Let us know Last updated on January 21, 2026


