PT-2026-44415 · Hono · Hono

Offset

·

Published

2026-05-28

·

Updated

2026-06-04

·

CVE-2026-47675

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Hono versions prior to 4.12.21
Description The serialize() function in hono/cookie fails to validate the sameSite and priority options against characters that can corrupt Set-Cookie header syntax, such as semicolons, carriage returns, and line feeds. While validation is applied to domain and path options, the lack of similar checks for these specific options allows an application passing user-controlled input to produce a Set-Cookie response header containing attacker-chosen additional attributes.
Recommendations Update to version 4.12.21.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47675
GHSA-3HRH-PFW6-9M5X

Affected Products

Hono