Junglewise Threat Intelligence

CVE-2026-39410: Hono cookie prefix bypass via name normalization in getCookie

CVE-2026-39410 · Severity: medium · CVSS 4.8 · Published 2026-04-08

Technologies: Honojs Hono. Vendors: npm.

Executive brief

Hono is a web application framework used to build JavaScript-based websites and services. A flaw in how it handles browser cookies allows an attacker to potentially bypass security protections (like the __Secure- and __Host- prefixes) by using special characters that the framework incorrectly cleans up. This could allow an attacker to override legitimate user cookies, potentially leading to session hijacking or unauthorized access to user accounts.

Technical details

A vulnerability exists in Hono's cookie parsing logic where the parse() function (used by getCookie()) incorrectly normalized cookie names using JavaScript's trim() method. While browsers following RFC 6265bis only trim standard spaces and tabs, Hono's use of trim() also removed characters like the non-breaking space (U+00A0). An attacker capable of setting cookies can use these characters to create a cookie name that the browser sees as unique but Hono normalizes to match an existing, sensitive cookie name. This allows the attacker to override legitimate cookies and bypass __Secure- or __Host- prefix protections, potentially leading to session fixation or hijacking. The issue is fixed in version 4.12.12 by aligning the parsing logic with browser standards.

Affected products

  • honojs Hono < 4.12.12

Timeline

  • 2026-04-07: patched: Fixed in version 4.12.12
  • 2026-04-08: disclosed: Advisory published by GitHub and NVD

References

Related threats