{"id":"CVE-2026-81888","title":"@hono/oauth-providers is Authentication middleware for Hono","summary":"@hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is absent on both sides, so the anti-CSRF check passes for a ca…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","cwe":["CWE-352","CWE-1275"],"vendor":"hono","product":"@hono/oauth-providers","affected":["@hono/oauth-providers < 0.8.6"],"patched":["@hono/oauth-providers 0.8.6"],"published":"2026-08-31","updated":"2026-09-09","sourceUpdated":"2026-09-09T21:09:13.080","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81888","references":[{"url":"https://github.com/honojs/middleware/commit/b37765f40b7bddb1d8fce39573b085222dea58c1","label":"security-advisories@github.com"},{"url":"https://github.com/honojs/middleware/pull/2040","label":"security-advisories@github.com"},{"url":"https://github.com/honojs/middleware/releases/tag/%40hono%2Foauth-providers%400.8.6","label":"security-advisories@github.com"},{"url":"https://github.com/honojs/middleware/security/advisories/GHSA-fm3f-ch8h-qw8q","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-fm3f-ch8h-qw8q"}],"tags":["nvd","ghsa","npm"],"epss":0.00149,"epssPercentile":0.04447,"aliases":["GHSA-fm3f-ch8h-qw8q"],"ecosystem":"npm","ingestedAt":"2026-08-31T21:14:21.293Z","slug":"CVE-2026-81888","body":"## Overview\n\n@hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is absent on both sides, so the anti-CSRF check passes for a callback that never came from a genuine login attempt. This defeats the `state`-based CSRF protection under default usage. Version 0.8.6 has a patch.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-81888)\n\nAffected packages:\n\n- `@hono/oauth-providers < 0.8.6`\n\nPatched in:\n\n- `@hono/oauth-providers 0.8.6`\n\nSource: https://github.com/advisories/GHSA-fm3f-ch8h-qw8q","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}