Vulnerability Description
Hono before 4.10.2 (fixed in 4.10.3) contains a flaw in its CORS middleware: when the origin is not set to "*", the middleware copies the Vary header from the incoming request into the response. Because Vary is a response header that should be managed by the server, an attacker can supply arbitrary Vary values that are reflected into the response, potentially causing cache key pollution and inconsistent CORS enforcement in environments that rely on shared caches or proxies.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/honojs/hono/security/advisories/GHSA-q7jf-gf43-6x6p
- https://www.vulncheck.com/advisories/hono-vary-header-injection-in-cors-middlewa
FAQ
What is CVE-2025-71381?
CVE-2025-71381 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Hono before 4.10.2 (fixed in 4.10.3) contains a flaw in its CORS middleware: when the origin is not set to "*", the middleware copies the Vary header from the incoming request into the response. Becau...
How severe is CVE-2025-71381?
CVE-2025-71381 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-71381?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.