CVE-2025-71381Medium· 4.2▾ SunlitHono vulnerable to Vary Header Injection leading to potential CORS Bypass
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.3%
A flaw in the CORS middleware allowed request Vary headers to be reflected into the response, enabling attacker-controlled Vary values and potentially affecting cache behavior.
The middleware previously copied the Vary header from the request when origin was not set to "*". Since Vary is a response header that should only be managed by the server, this could allow an attacker to influence caching behavior or cause inconsistent CORS handling.
Most environments will see impact only when shared caches or proxies rely on the Vary header. The practical effect varies by configuration.
May cause cache key pollution and inconsistent CORS enforcement in certain setups. No direct confidentiality, integrity, or availability impact in default configurations.
Update to the latest patched release. The CORS middleware has been corrected to handle Vary exclusively as a response header.
hono < 4.10.3Upgrade to a patched release:
hono 4.10.3Connected by shared product, vendor, weakness, or advisory.
GHSA-cw3j-28qq-x3xhMedium· 6.5Duplicate Advisory: Hono vulnerable to Vary Header Injection leading to potential CORS Bypass
CVE-2026-84363Medium· 5.9Hono is a Web application framework that provides support for any JavaScript runtime
GHSA-3wcj-gjvf-fvchMedium· 4.8Duplicate Advisory: Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })
GHSA-6623-4q32-82v8Low· 4.7Duplicate Advisory: hono/jsx renders plain strings unescaped in boundary components, leading to XSS
GHSA-55cm-p4ww-685gMedium· 5.3Duplicate Advisory: Hono missing validation of cookie name on write path in setCookie()
CVE-2026-56762Medium· 5.3Hono missing validation of cookie name on write path in setCookie()