{"id":"CVE-2026-59896","summary":"hono/jsx does not isolate context per request, leading to cross-request data disclosure","details":"Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a different in-flight request to be used after an await in an async component. This issue is fixed in version 4.12.27.","aliases":["GHSA-hvrm-45r6-mjfj"],"modified":"2026-07-15T01:49:14.084740883Z","published":"2026-07-08T16:08:07.975Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59896.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-362"]},"references":[{"type":"WEB","url":"https://github.com/honojs/hono/releases/tag/v4.12.27"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59896.json"},{"type":"ADVISORY","url":"https://github.com/honojs/hono/security/advisories/GHSA-hvrm-45r6-mjfj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59896"},{"type":"FIX","url":"https://github.com/honojs/hono/commit/fab3b13639339cbd5ba1166a5b23d9ac30c5f64f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/honojs/hono","events":[{"introduced":"5ca5c3e9764486b31ad7db4c0c19b2c926753ae3"},{"fixed":"97c6fe1f12298c715eb7b2da65b4b6e0d81682bb"},{"fixed":"fab3b13639339cbd5ba1166a5b23d9ac30c5f64f"}],"database_specific":{"extracted_events":[{"introduced":"4.11.8"},{"fixed":"4.12.27"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:hono:hono:*:*:*:*:*:node.js:*:*"}}],"versions":["v4.12.26","v4.12.25","v4.12.24","v4.12.23","v4.12.22","v4.12.21","v4.12.20","v4.12.19","v4.12.18","v4.12.17","v4.12.16","v4.12.15","v4.12.14","v4.12.13","v4.12.12","v4.12.11","v4.12.10","v4.12.9","v4.12.8","v4.12.7","v4.12.6","v4.12.5","v4.12.4","v4.12.3","v4.12.2","v4.12.1","v4.12.0","v4.11.10","v4.11.9","v4.11.8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59896.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"}]}