CVE-2026-39410Disclosure(hono / hono)

LOWCVSS 4.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch hono hono systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy between browser cookie parsing and parse() handling allows cookie prefix protections to be bypassed. Cookie names that are treated as distinct by the browser may be normalized to the same key by parse(), allowing attacker-controlled cookies to override legitimate ones. This vulnerability is fixed in 4.12.12.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hono

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-08); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
hono

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-08: 2Mentions · 2026-04-20: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-20: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-20: 104-0804-20
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-082
Disclosure1Patch1
2026-04-201
Disclosure1
Full discourse3 posts
  • GMO Flatt Security株式会社@flatt_security
    Disclosure

    弊社エンジニアの報告した脆弱性が4件公開されました。アドバイザリを参照し最新版へのアップデート等の対策を行ってください。 セキュリティエンジニア @koketiki 報告 ① CVE-2026-39410(HonoにおけるCookie Prefix保護のバイパス) https://flatt.tech/cve/CVE-2026-39410 セキュリティエンジニア @k1rnt 報告 ② CVE-2026-33810(Goのcrypto/x509におけるDNS名制約検証の大文字・小文字不一致によるバイパス) https://flatt.tech/cve/CVE-2026-33810 コーポレートエンジニア @hamayanhamayan 報告 ③ CVE-2026-3429(Keycloakにおけるアクセス制御不備) https://flatt.tech/cve/CVE-2026-3429 ④ CVE-2026-28871(WebKitにおけるXSSに繋がりうるロジックの脆弱性) https://flatt.tech/cve/CVE-2026-28871

    Post summary

    Company engineers disclosed four new CVEs, urging users to review advisories and apply updates to address the identified vulnerabilities.

    08436810.8K
    5.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-39410 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy between browser cookie parsing and parse() handl… https://www.cve.org/CVERecord?id=CVE-2026-39410 ----- Traducción: CVE-2026-39410 Hon… http://infoflow.cloud`

    Post summary

    A short notification about CVE‑2026‑39410 that links to the official CVE record but offers no additional technical or exploit information.

    0000034
    67 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-39410 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy between browser cookie parsing and parse() handl… https://www.cve.org/CVERecord?id=CVE-2026-39410

    Post summary

    CVE-2026-39410 impacts the Hono framework before version 4.12.12 due to a cookie parsing discrepancy; upgrading to 4.12.12 resolves the issue.

    00000131
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphonohono-node.js-

Explore more