GHSA-cw3j-28qq-x3xh

Suggest an improvement
Source
https://github.com/advisories/GHSA-cw3j-28qq-x3xh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-cw3j-28qq-x3xh/GHSA-cw3j-28qq-x3xh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-cw3j-28qq-x3xh
Downstream
CGA (14)
Withdrawn
2026-10-02T18:28:39Z
Published
2026-07-01T00:34:02Z
Modified
2026-10-02T18:45:04Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Duplicate Advisory: Hono vulnerable to Vary Header Injection leading to potential CORS Bypass
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-q7jf-gf43-6x6p. This link is maintained to preserve external references.

Original Description

Hono before 4.10.2 (fixed in 4.10.3) contains a flaw in its CORS middleware: when the origin is not set to "*", the middleware copies the Vary header from the incoming request into the response. Because Vary is a response header that should be managed by the server, an attacker can supply arbitrary Vary values that are reflected into the response, potentially causing cache key pollution and inconsistent CORS enforcement in environments that rely on shared caches or proxies.

Database specific
{
    "cwe_ids": [
        "CWE-113"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-02T18:28:39Z",
    "nvd_published_at": "2026-06-30T23:16:52Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / hono

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

last_known_affected_version_range
"< 4.10.3"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-cw3j-28qq-x3xh/GHSA-cw3j-28qq-x3xh.json"