PT-2026-56506 · Hono · Hono
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Hono versions 4.11.8 through 4.12.26
Description
During server-side rendering, the
hono/jsx module fails to isolate context values on a per-request basis. This allows data from a different in-flight request to be accessed after an await operation within an async component. The affected functions include createContext(), useContext(), jsxRenderer(), and useRequestContext().Recommendations
Update Hono to version 4.12.27.
Exploit
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hono