VYPR

Hono

by Npm

Source repositories

CVEs (1)

  • CVE-2026-56762MedJun 23, 2026
    risk 0.27cvss 5.3epss 0.00

    Hono before 4.12.12 does not validate cookie names on the write path in the setCookie(), serialize(), and serializeSigned() functions, allowing invalid characters such as control characters (e.g. \r or \n) when an application passes a user-controlled cookie name. This can…