GHSA-cw3j-28qq-x3xhMedium· 6.5▾ SunlitDuplicate Advisory: Hono vulnerable to Vary Header Injection leading to potential CORS Bypass
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-q7jf-gf43-6x6p. This link is maintained to preserve external references.
Hono before 4.10.2 (fixed in 4.10.3) contains a flaw in its CORS middleware: when the origin is not set to "*", the middleware copies the Vary header from the incoming request into the response. Because Vary is a response header that should be managed by the server, an attacker can supply arbitrary Vary values that are reflected into the response, potentially causing cache key pollution and inconsistent CORS enforcement in environments that rely on shared caches or proxies.
hono < 4.10.3Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-71381Medium· 4.2Hono vulnerable to Vary Header Injection leading to potential CORS Bypass
GHSA-55cm-p4ww-685gMedium· 5.3Duplicate Advisory: Hono missing validation of cookie name on write path in setCookie()
CVE-2026-56762Medium· 5.3Hono missing validation of cookie name on write path in setCookie()
GHSA-3wcj-gjvf-fvchMedium· 4.8Duplicate Advisory: Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })
GHSA-6623-4q32-82v8Low· 4.7Duplicate Advisory: hono/jsx renders plain strings unescaped in boundary components, leading to XSS
CVE-2026-93981Medium· 4.7hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the roo…