An open index of dependabot pull requests across open source projects.

Hono missing validation of cookie name on write path in setCookie()

RSS Feed MODERATE
GHSA-26pp-8wgv-hjvm
Description:

Summary

Cookie names are not validated on the write path when using setCookie(), serialize(), or serializeSigned() to generate Set-Cookie headers.

While certain cookie attributes such as domain and path are validated, the cookie name itself may contain invalid characters.

This results in inconsistent handling of cookie names between parsing (read path) and serialization (write path).

Details

When applications use setCookie(), serialize(), or serializeSigned() with a user-controlled cookie name, invalid values (e.g., containing control characters such as \r or \n) can be used to construct malformed Set-Cookie header values.

For example:

Set-Cookie: legit
X-Injected: evil=value

However, in modern runtimes such as Node.js and Cloudflare Workers, such invalid header values are rejected and result in a runtime error before the response is sent.

As a result, the reported header injection / response splitting behavior could not be reproduced in these environments.

Impact

Applications that pass untrusted input as the cookie name to setCookie(), serialize(), or serializeSigned() may encounter runtime errors due to invalid header values.

In tested environments, malformed Set-Cookie headers are rejected before being sent, and the reported header injection behavior could not be reproduced.

This issue primarily affects correctness and robustness rather than introducing a confirmed exploitable vulnerability.

Affected Packages
Ecosystem Package Vulnerable Versions Patched Version
npm hono < 4.12.12
4.12.12
Related Dependabot Pull Requests
deps(deps): bump the security-patches group across 4 directories with 2 updates
Open 14 days ago
VeVarunSharma/contoso-vibe-engineering #303
npm:drizzle-orm npm:hono
VeVarunSharma
chore(deps): bump the npm_and_yarn group across 11 directories with 24 updates
Open 15 days ago
GlacierEQ/langgraphjs #6
npm:axios npm:vite +20 more
GlacierEQ
deps(deps): bump the security-patches group across 4 directories with 2 updates
Closed 15 days ago
VeVarunSharma/contoso-vibe-engineering #296
npm:drizzle-orm npm:hono
VeVarunSharma
build(deps): Bump the npm_and_yarn group across 1 directory with 15 updates
Closed 15 days ago
you112ef/knet-mock-pay-06 #17
npm:react-router npm:vite +12 more
you112ef
chore(deps): bump the npm_and_yarn group across 5 directories with 23 updates
Closed 16 days ago
nssuwan186-dev/ag-ui #35
npm:next npm:uuid +4 more
nssuwan186-dev
chore(deps): bump the npm_and_yarn group across 24 directories with 5 updates
Open 16 days ago
jadenblack/composio #101
npm:axios npm:uuid +2 more
jadenblack
Bump the npm_and_yarn group across 5 directories with 7 updates
Open 16 days ago
rshan1515/workers-sdk #19
npm:vite npm:undici +5 more
rshan1515
Bump the npm_and_yarn group across 4 directories with 9 updates
Closed 16 days ago
ANT0071/drizzle-orm #6
npm:rollup npm:uuid +4 more
ANT0071
build(deps): bump the npm_and_yarn group across 2 directories with 5 updates
Open 16 days ago
tsukasa-u/FUSOU #177
npm:astro npm:vite +3 more
tsukasa-u
chore(deps): bump the npm_and_yarn group across 9 directories with 8 updates
Closed 16 days ago
bluluvinn/x402 #16
npm:axios npm:vite +5 more
bluluvinn
chore(deps): Bump the npm_and_yarn group across 4 directories with 5 updates
Closed 17 days ago
ds1/pincerpay #110
npm:next npm:yaml +3 more
ds1
Bump the npm_and_yarn group across 4 directories with 7 updates
Open 17 days ago
rshan1515/workers-sdk #18
npm:vite npm:undici +5 more
rshan1515
chore(deps): bump the npm_and_yarn group across 15 directories with 10 updates
Closed 18 days ago
ANT0071/mastra #97
npm:axios npm:next +6 more
ANT0071
chore(deps): bump the npm_and_yarn group across 15 directories with 9 updates
Closed 18 days ago
xendit/mastra #101
npm:axios npm:next +5 more
xendit
Bump the npm_and_yarn group across 19 directories with 5 updates
Open 19 days ago
cloudflare/ai #520
npm:axios npm:postcss +3 more
cloudflare
Bump the npm_and_yarn group across 1 directory with 5 updates
Closed 20 days ago
canstralian/workers-for-platforms-template #1
npm:undici npm:esbuild +2 more
canstralian
Bump the npm_and_yarn group across 18 directories with 4 updates
Open 20 days ago
cloudflare/ai #514
npm:axios npm:postcss +2 more
cloudflare
deps(deps): bump the security-patches group across 3 directories with 2 updates
Open 21 days ago
VeVarunSharma/contoso-vibe-engineering #279
npm:drizzle-orm npm:hono
VeVarunSharma
chore(deps): Bump hono from 4.11.4 to 4.12.14
Closed 21 days ago
paveg/tailf #46
npm:hono
paveg
build(deps): bump the npm_and_yarn group across 9 directories with 9 updates
Closed 21 days ago
sc-shakyawijerathne/xmcloud-starter-js #77
npm:axios npm:next +4 more
sc-shakyawijerathne
chore(deps): bump the npm_and_yarn group across 1 directory with 5 updates
Closed 21 days ago
tenkumogroup/guildkit #71
npm:next npm:fast-xml-parser +3 more
tenkumogroup
build(deps): bump the npm_and_yarn group across 1 directory with 23 updates
Open 22 days ago
johnnycsv232/GettUppENTERPRISE #9
npm:vite npm:next +21 more
johnnycsv232
chore(deps): bump hono from 3.11.8 to 4.12.14 in the npm_and_yarn group across 1 directory
Closed 24 days ago
lmist/markmap #1
npm:hono
lmist
chore(deps): bump the npm_and_yarn group across 2 directories with 10 updates
Open 24 days ago
mdjahid11978-design/voltagent #7
npm:axios npm:yaml +6 more
mdjahid11978-design
chore(deps): bump the npm_and_yarn group across 4 directories with 11 updates
Closed 24 days ago
aknibircse/dokploy-serverless #31
npm:next npm:undici +7 more
aknibircse
build(deps): bump the npm_and_yarn group across 1 directory with 3 updates
Open 25 days ago
crisesarmiento/vision-total-ar #19
npm:next npm:hono +1 more
crisesarmiento
build(deps): bump the npm_and_yarn group across 2 directories with 5 updates
Open 25 days ago
clouet-remi/Projet-de-fin-de-formation---Blablabook- #4
npm:vite npm:next +3 more
clouet-remi
chore(deps): bump the npm_and_yarn group across 2 directories with 4 updates
Open 25 days ago
traceroot-ai/traceroot-ts #75
npm:hono npm:protobufjs +2 more
traceroot-ai
Bump hono from 4.11.5 to 4.12.14
Closed 25 days ago
krsjenmt/krsjen.ai #56
npm:hono
krsjenmt
build(deps): bump the npm_and_yarn group across 1 directory with 8 updates
Closed 26 days ago
jonmatum/serverless-second-brain #50
npm:vite npm:next +6 more
jonmatum
chore(deps): bump the npm_and_yarn group across 4 directories with 10 updates
Closed 26 days ago
aknibircse/dokploy-serverless #30
npm:next npm:undici +6 more
aknibircse
chore(deps): bump the npm_and_yarn group across 4 directories with 9 updates
Closed 26 days ago
paulpham157/dokploy #36
npm:next npm:undici +7 more
paulpham157
chore(deps): bump the npm_and_yarn group across 3 directories with 12 updates
Open 27 days ago
nexusct/moltbot #2
npm:vite npm:undici +8 more
nexusct
chore(deps): bump hono from 4.12.0 to 4.12.14
Open 27 days ago
bl1nk-bot/agent-library #24
npm:hono
bl1nk-bot
build(deps): bump the npm_and_yarn group across 1 directory with 12 updates
Closed 27 days ago
inthepocket/cookie-though #1243
npm:astro npm:vite +10 more
inthepocket
chore(deps): bump hono from 4.12.0 to 4.12.14
Open 27 days ago
Merfy-Dropshipping-Platform/merfy-islands #23
npm:hono
Merfy-Dropshipping-Platform
build(deps): bump the npm_and_yarn group across 2 directories with 10 updates
Open 28 days ago
google/perfetto #5518
npm:lodash npm:path-to-regexp +7 more
google
chore(deps): bump the all-minor-and-patch group across 1 directory with 24 updates
Open 28 days ago
TiM1113/FoodDelivery-AWS-Vercell #132
npm:vitest npm:@vitest/coverage-v8 +22 more
TiM1113
chore(deps): bump the npm_and_yarn group across 3 directories with 9 updates
Closed 28 days ago
conor-spec/goose #1
npm:vite npm:webpack +7 more
conor-spec
Bump the npm_and_yarn group across 1 directory with 3 updates
Closed 28 days ago
selfagency/teamdynamix-mcp #1
npm:vite npm:hono +1 more
selfagency
build(deps): bump hono from 4.12.0 to 4.12.14
Closed 28 days ago
HerbCaudill/briefings #4
npm:hono
HerbCaudill
chore(deps): bump the npm_and_yarn group across 1 directory with 5 updates
Open 28 days ago
klodr/gmail-mcp #5
npm:nodemailer npm:path-to-regexp +3 more
klodr
Bump hono from 4.11.7 to 4.12.14 in the npm_and_yarn group across 1 directory
Open 29 days ago
hashicorp-japan/terraform-workshop-jp #79
npm:hono
hashicorp-japan
chore(deps): Bump the backend-deps group across 1 directory with 7 updates
Closed 29 days ago
marylin/whateverops #61
npm:@supabase/supabase-js npm:resend +5 more
marylin
chore(deps): bump hono from 4.12.8 to 4.12.14
Open 29 days ago
dothackerman/ls-oneup #38
npm:hono
dothackerman
chore(deps): bump the minor-and-patch group across 1 directory with 12 updates
Closed 29 days ago
ComeOnOliver/skillshub #58
npm:@types/node npm:react-dom +10 more
ComeOnOliver
deps(deps): bump the production-dependencies group across 1 directory with 27 updates
Closed 29 days ago
italicninja/blog #195
npm:react-dom npm:next +14 more
italicninja
chore(deps): Bump hono from 4.6.0 to 4.12.14
Open 29 days ago
amynaff/my-lunar-phase #33
npm:hono
amynaff
chore(deps): bump hono from 4.12.9 to 4.12.14
Open 29 days ago
kweinmeister/hono-cars-api #13
npm:hono
kweinmeister
Bump hono from 4.11.1 to 4.12.14
Open 29 days ago
sk1b-yak/vite-react-template #2
npm:hono
sk1b-yak
Advisory Details
Published: April 08, 2026 about 1 month ago
Updated: April 08, 2026 about 1 month ago
CVSS Score: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Source: Github
Classification: GENERAL
UUID: GSA_kwCzR0hTQS0yNnBwLTh3Z3YtaGp2bc4ABU3n
PR Statistics
PR Status
Open 563 (43.7%)
Merged 0 (0.0%)
Closed 724 (56.3%)
Update Types
Major 151 (5.0%)
Minor 1175 (39.1%)
Patch 1665 (55.4%)