Saad Fellahi@SaadFellahiiPatch
The tweet announces three CVEs affecting Hono.js v4.12.4 and Fastify v5.8.1, notes that vendors have issued quick fixes, and indicates detailed write‑ups will follow soon.
DailyCVE@dailycveDisclosure
The post releases details about CVE‑2026‑29086, naming it a medium‑severity Cookie Attribute Injection vulnerability.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A new cookie injection vulnerability (CVE-2026-29086) affecting Hono Web Framework before version 4.12.4 has been disclosed, with technical details provided but no PoC, exploit, or patch information available.
Infoflowcloud@infoflowcloudDisclosure
CVE‑2026‑29086 is reported with basic technical details (setCookie() semicolon validation issue) and a link to the CVE record, but lacks a PoC, exploit code, or claim of active exploitation.
CVE@CVEnewPatch
CVE-2026-29086 involves Hono's setCookie() utility failing to validate semicolons, fixed in version 4.12.4.