Medium severity5.3GHSA Advisory· Published May 13, 2026· Updated May 13, 2026
CVE-2026-44457
CVE-2026-44457
Description
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware does not skip caching for responses that declare per-user variance via Vary: Authorization or Vary: Cookie. As a result, a response cached for one authenticated user may be served to subsequent requests from different users. This vulnerability is fixed in 4.12.18.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
hononpm | < 4.12.18 | 4.12.18 |
Affected products
18- osv-coords17 versionspkg:apk/chainguard/hono-service-command-routerpkg:apk/chainguard/kibana-9.1pkg:apk/chainguard/kibana-9.1-iamguardedpkg:apk/chainguard/kibana-9.3pkg:apk/chainguard/kibana-9.3-iamguardedpkg:apk/chainguard/kibana-9.4pkg:apk/chainguard/kibana-9.4-iamguardedpkg:apk/chainguard/langfuse-3-workerpkg:apk/chainguard/langfuse-fips-3-workerpkg:apk/chainguard/librechatpkg:apk/chainguard/opensearch-dashboards-2pkg:apk/chainguard/opensearch-dashboards-2-fipspkg:apk/chainguard/wazuh-dashboardpkg:apk/chainguard/wazuh-dashboard-fipspkg:apk/wolfi/langfuse-3-workerpkg:apk/wolfi/opensearch-dashboards-2pkg:npm/hono
< 0+ 16 more
- (no CPE)range: < 0
- (no CPE)range: < 9.1.10-r15
- (no CPE)range: < 9.1.10-r15
- (no CPE)range: < 9.3.4-r4
- (no CPE)range: < 9.3.4-r4
- (no CPE)range: < 9.4.2-r0
- (no CPE)range: < 9.4.2-r0
- (no CPE)range: < 3.176.0-r0
- (no CPE)range: < 3.176.0-r0
- (no CPE)range: < 0.8.4-r6
- (no CPE)range: < 2.19.5-r11
- (no CPE)range: < 2.19.5-r11
- (no CPE)range: < 4.14.4-r4
- (no CPE)range: < 4.14.4-r3
- (no CPE)range: < 3.176.0-r0
- (no CPE)range: < 2.19.5-r11
- (no CPE)range: < 4.12.18
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-p77w-8qqv-26rmghsaADVISORY
- github.com/honojs/hono/security/advisories/GHSA-p77w-8qqv-26rmnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-44457ghsaADVISORY
News mentions
0No linked articles in our index yet.