Improper Encoding or Escaping of Output Affecting hono package, versions <4.12.25


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-HONO-17356429
  • published17 Jun 2026
  • disclosed16 Jun 2026
  • creditRootingg

Introduced: 16 Jun 2026

NewCVE-2026-54287  (opens in a new tab)
CWE-116  (opens in a new tab)

How to fix?

Upgrade hono to version 4.12.25 or higher.

Overview

hono is an Ultrafast web framework for the Edges

Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output in the AWS Lambda adapter's handling of multiple Set-Cookie headers. An attacker can cause clients to drop or misinterpret cookies by triggering responses that set multiple cookies, leading to broken sessions, forced re-authentication, or failure of preference and CSRF cookies. This is only exploitable if the application is deployed on AWS Lambda behind an ALB in single-header mode or VPC Lattice v2.

CVSS Base Scores

version 4.0
version 3.1