Improper Encoding or Escaping of Output in hono - CVE-2026-54287
Published: July 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to modify data on the system.
The vulnerability exists due to on AWS Lambda, the ALB single-header response and the VPC Lattice v2 response join multiple Set-Cookie headers into one comma-separated value. Because commas also appear inside cookie attributes (for example Expires dates), clients cannot split the value back into individual cookies and silently drop or misparse them. A remote attacker can trigger improper encoding or escaping of output to modify data on the system.
Affected software
Informix Dynamic Server
IBM App Connect Enterprise
How to mitigate CVE-2026-54287
Informix Dynamic Server - addressed in versions 14.10.FC14, 15.0.1.14
IBM App Connect Enterprise - update to 13.0.8.0