---
id: CVE-2025-71381
aliases:
  - GHSA-q7jf-gf43-6x6p
title: Hono vulnerable to Vary Header Injection leading to potential CORS Bypass
summary: Hono vulnerable to Vary Header Injection leading to potential CORS Bypass
severity: medium
cvss: 4.2
cwe:
  - CWE-444
vendor: hono
product: hono
ecosystem: npm
affected:
  - hono < 4.10.3
patched:
  - hono 4.10.3
published: '2025-10-24'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T18:28:56Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-q7jf-gf43-6x6p'
references:
  - url: 'https://github.com/honojs/hono/security/advisories/GHSA-q7jf-gf43-6x6p'
  - url: >-
      https://github.com/honojs/hono/commit/d9b8b4b73b4f997994f2764013207365fe711282
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-71381'
  - url: >-
      https://www.vulncheck.com/advisories/hono-vary-header-injection-in-cors-middleware
  - url: 'https://github.com/advisories/GHSA-q7jf-gf43-6x6p'
tags:
  - ghsa
  - npm
epss: 0.00292
epssPercentile: 0.19755
ingestedAt: '2026-10-02T22:33:09.857Z'
---

## Overview

### Summary  
A flaw in the CORS middleware allowed request `Vary` headers to be reflected into the response, enabling attacker-controlled `Vary` values and potentially affecting cache behavior.

### Details  
The middleware previously copied the `Vary` header from the request when `origin` was not set to `"*"`.  Since `Vary` is a response header that should only be managed by the server, this could allow an attacker to influence caching behavior or cause inconsistent CORS handling.

Most environments will see impact only when shared caches or proxies rely on the `Vary` header. The practical effect varies by configuration.

### Impact  
May cause cache key pollution and inconsistent CORS enforcement in certain setups. No direct confidentiality, integrity, or availability impact in default configurations.  

### Resolution  
Update to the latest patched release. The CORS middleware has been corrected to handle `Vary` exclusively as a response header.

## Affected packages

- `hono < 4.10.3`

## Remediation

Upgrade to a patched release:

- `hono 4.10.3`
