SB2026072463 - Insufficient verification of data authenticity in hono



SB2026072463 - Insufficient verification of data authenticity in hono

Published: July 24, 2026

Security Bulletin ID SB2026072463
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Insufficient verification of data authenticity (CVE-ID: CVE-2025-71381)

CWE-ID: CWE-345 - Insufficient Verification of Data Authenticity

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to influence caching behavior and cause inconsistent CORS handling.

The vulnerability exists due to improper handling of response headers in the CORS middleware when processing requests with attacker-controlled Vary headers. A remote attacker can send a specially crafted request to influence caching behavior and cause inconsistent CORS handling.

Impact is primarily observed in deployments that use shared caches or proxies relying on the Vary header.


Remediation

Install update from vendor's website.