Junglewise Threat Intelligence

CVE-2025-71381: Hono CORS middleware Vary header injection

CVE-2025-71381 · Severity: medium · CVSS 6.5 · Published 2026-06-30

Technologies: hono (npm). Vendors: Hono, npm.

Executive brief

Hono, a popular web framework, contains a flaw in its Cross-Origin Resource Sharing (CORS) security component. An attacker can manipulate how the server communicates with web caches and proxies by injecting custom headers into the server's response. This can lead to cache pollution, where legitimate users receive incorrect or restricted content, potentially bypassing intended security restrictions.

Technical details

A vulnerability exists in the Hono CORS middleware when the 'origin' configuration is set to something other than '*'. The middleware incorrectly copies the 'Vary' header from the incoming HTTP request and reflects it into the HTTP response. Because 'Vary' is intended to be a server-managed response header that dictates cache key generation, this reflection allows an attacker to perform header injection. By providing arbitrary values, an attacker can cause cache key pollution or force inconsistent CORS enforcement in environments utilizing shared caches or intermediate proxies. The issue is classified as CWE-113 (Improper Neutralization of CRLF Sequences in HTTP Headers) and is resolved in version 4.10.3.

Affected products

  • Hono Hono < 4.10.2

Timeline

  • 2025-10-24: advisory: GitHub Security Advisory published
  • 2026-06-30: disclosed: NVD publication date

References

Related threats