{"id":"CVE-2026-54287","aliases":["GHSA-j6c9-x7qj-28xf"],"title":"hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice","summary":"hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice","severity":"medium","cvss":5.3,"cwe":["CWE-116"],"vendor":"hono","product":"hono","ecosystem":"npm","affected":["hono < 4.12.25"],"patched":["hono 4.12.25"],"published":"2026-06-16","updated":"2026-06-16","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-j6c9-x7qj-28xf","references":[{"url":"https://github.com/honojs/hono/security/advisories/GHSA-j6c9-x7qj-28xf"},{"url":"https://github.com/advisories/GHSA-j6c9-x7qj-28xf"}],"tags":["ghsa","npm"],"epss":0.0031,"epssPercentile":0.21219,"ingestedAt":"2026-07-07T15:41:58.362Z","slug":"CVE-2026-54287","body":"## Overview\n\n### Summary\n\nOn AWS Lambda, the ALB single-header response and the VPC Lattice v2 response join multiple `Set-Cookie` headers into one comma-separated value. Because commas also appear inside cookie attributes (for example `Expires` dates), clients cannot split the value back into individual cookies and silently drop or misparse them.\n\n### Details\n\nPer RFC 6265, each cookie must be its own `Set-Cookie` header line, and commas may appear inside attribute values. Joining cookies with `\", \"` collides with those commas, producing a value that clients cannot reliably split. Only ALB single-header mode and VPC Lattice v2 are affected; API Gateway v1/v2 and ALB with multi-value headers enabled already use an array and are unaffected.\n\n### Impact\n\nA client may receive only one of the cookies, a malformed cookie, or none. Session, CSRF, or preference cookies can silently fail to apply, breaking sessions or forcing re-authentication. This affects applications that set multiple cookies per response and run on AWS Lambda behind an ALB in single-header mode (the default) or VPC Lattice v2.\n\n## Affected packages\n\n- `hono < 4.12.25`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `hono 4.12.25`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}