Insufficient verification of data authenticity in hono - CVE-2025-71381

 

Insufficient verification of data authenticity in hono - CVE-2025-71381

Published: July 24, 2026


Vulnerability identifier: #VU139323
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-71381
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to influence caching behavior and cause inconsistent CORS handling.

The vulnerability exists due to improper handling of response headers in the CORS middleware when processing requests with attacker-controlled Vary headers. A remote attacker can send a specially crafted request to influence caching behavior and cause inconsistent CORS handling.

Impact is primarily observed in deployments that use shared caches or proxies relying on the Vary header.


Affected software

hono

How to mitigate CVE-2025-71381

Install security update from vendor's website.

hono - update to 4.10.3

External References

Related Security Bulletins