VYPR
Unrated severityNVD Advisory· Published Jul 11, 2026· Updated Jul 14, 2026

Hono - Prototype Pollution via __proto__ Key in parseBody with dot Option

CVE-2026-56763

Description

Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field names to create objects with __proto__ properties. When parsed results are merged into regular JavaScript objects using unsafe merge patterns, attackers can exploit this to achieve prototype pollution and modify object behavior.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.