CVE-2025-66803

CVE-2025-66803 is a low-severity race condition vulnerability in @hotwired/turbo (npm), affecting versions <= 8.0.20. It is fixed in 8.0.21.

Does this CVE actually affect you?

Kodem shows which CVEs are reachable and running in your applications, so you fix what's exploitable, not just what's listed.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Runtime intelligence, not another scanner.

Summary

Turbo Frame responses can restore stale session cookies

A race condition in Turbo Frames allows delayed HTTP responses to restore stale session cookies after session-modifying operations.

Details

Browsers automatically process Set-Cookie headers from HTTP responses. When a Turbo Frame request is in-flight during a session-modifying action (such as logout), the delayed response may include a Set-Cookie header reflecting the session state at request time. This can result in stale session cookies being restored after the session was intentionally modified or invalidated.

This condition can occur naturally on slow networks. An active network attacker capable of delaying responses could potentially exploit this to restore previous session state.

Impact

Applications using Turbo Frames with cookie-based session storage may experience:

  • Session state reversion after logout
  • Unintended restoration of previous authentication state

The impact is limited to applications using client-side cookie storage for sessions. Applications using server-side session stores (Redis, database, etc.) are not meaningfully affected, as the server-side session state remains authoritative.

Workarounds

  • Use server-side session storage instead of a cookie store like Rails's cookie store
    • Ensure logout flows remove or disable Turbo Frame elements before invalidating sessions

References

Impact

Multiple concurrent operations access a shared resource without proper synchronization, producing unpredictable results depending on timing. Typical impact: TOCTOU exploits, data corruption, or privilege escalation.

Affected versions

@hotwired/turbo (<= 8.0.20)

Security releases

@hotwired/turbo → 8.0.21 (npm)

Kodem intelligence

Severity tells you how bad this could be in the worst case. It does not tell you whether you are exposed. Exploitability and impact are functions of runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A vulnerable package can sit in your dependency tree and never run.

Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter. Kodem's runtime-powered SCA identifies whether this CVE is reachable in your applications.

Already deployed Kodem?

See it in your environmentNew to Kodem? Get a demo →

Remediation advice

Upgrade to Turbo 8.0.21 or later. The fix cancels in-flight Turbo Frame requests when:

  • The frame element is disconnected from the DOM
  • The frame's disabled attribute is set
  • The frame's src attribute is cleared

Frequently Asked Questions

  1. What is CVE-2025-66803? CVE-2025-66803 is a low-severity race condition vulnerability in @hotwired/turbo (npm), affecting versions <= 8.0.20. It is fixed in 8.0.21. Multiple concurrent operations access a shared resource without proper synchronization, producing unpredictable results depending on timing.
  2. Which versions of @hotwired/turbo are affected by CVE-2025-66803? @hotwired/turbo (npm) versions <= 8.0.20 is affected.
  3. Is there a fix for CVE-2025-66803? Yes. CVE-2025-66803 is fixed in 8.0.21. Upgrade to this version or later.
  4. Is CVE-2025-66803 exploitable, and should I be worried? Whether CVE-2025-66803 is exploitable in your environment depends on whether the vulnerable code is present and reachable. A CVSS score is a worst-case rating; it does not account for your specific deployment, configuration, or usage patterns. Kodem, an Intelligent Application Security platform, uses runtime intelligence to show which vulnerabilities actually execute in production, so you can focus on the ones that represent real risk. Get a demo
  5. What actually determines whether CVE-2025-66803 is exploitable, and how bad it is? Exploitability and impact are not fixed properties of a CVE. They depend on runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A high CVSS score on a dependency that never runs is not the same as real risk. Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter.
  6. How do I fix CVE-2025-66803? Upgrade @hotwired/turbo to 8.0.21 or later.

Stop the waste.
Protect your environment with Kodem.