Skip to main content
EPSS 0.3%top 80%

Hono vulnerable to Vary Header Injection leading to potential CORS Bypass (CVE-2025-71381)

0
Medium
Published: 10/24/2025 (10/24/2025, 19:15:13 UTC)
Source: GCVE Database
Product: hono

Description

A vulnerability in the Hono CORS middleware allowed attacker-controlled Vary headers from requests to be reflected in responses, potentially affecting cache behavior and causing inconsistent CORS enforcement. This issue impacts versions prior to 4.10.3. The vulnerability does not directly compromise confidentiality, integrity, or availability under default configurations but may lead to cache key pollution in environments using shared caches or proxies. A patch is available that corrects the middleware to manage the Vary header exclusively as a response header.

CVSS v3.1

Score 4.2medium

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected software

npmghsa
hono
Affected versions
<4.10.3

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/02/2026, 20:02:32 UTC

Technical Analysis

The Hono CORS middleware flaw (CVE-2025-71381) involves improper handling of the Vary header, where the middleware copied the Vary header from incoming requests into responses when the origin was not '*'. Since Vary is a response header that controls caching behavior, allowing attacker-controlled values can influence cache keys and cause inconsistent CORS enforcement. The impact depends on the caching infrastructure and proxy configurations. The issue affects Hono versions before 4.10.3 and has been fixed in a patched release.

Potential Impact

The vulnerability may cause cache key pollution and inconsistent Cross-Origin Resource Sharing (CORS) enforcement in environments that use shared caches or proxies relying on the Vary header. There is no direct impact on confidentiality, integrity, or availability in default setups. The practical effect varies based on deployment and caching configurations.

Mitigation Recommendations

Update Hono to version 4.10.3 or later where the CORS middleware has been corrected to handle the Vary header exclusively as a response header. Applying this official fix resolves the vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-q7jf-gf43-6x6p
Osv Schema Version
1.4.0
Aliases
["CVE-2025-71381"]
Ecosystems
["npm"]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6ac00d27a43b0b3b89fb1497

Added to database: 10/02/2026, 19:59:35 UTC

Last enriched: 10/02/2026, 20:02:32 UTC

Last updated: 10/03/2026, 04:45:56 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses