SB2026072463 - Insufficient verification of data authenticity in hono
Published: July 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Insufficient verification of data authenticity (CVE-ID: CVE-2025-71381)
CWE-ID: CWE-345 - Insufficient Verification of Data Authenticity
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to influence caching behavior and cause inconsistent CORS handling.
The vulnerability exists due to improper handling of response headers in the CORS middleware when processing requests with attacker-controlled Vary headers. A remote attacker can send a specially crafted request to influence caching behavior and cause inconsistent CORS handling.
Impact is primarily observed in deployments that use shared caches or proxies relying on the Vary header.
Remediation
Install update from vendor's website.