{"id":"GHSA-88fw-hqm2-52qc","summary":"hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard","details":"### Summary\n\nWith `credentials: true` and no explicit `origin` (the default wildcard), the CORS Middleware reflects the request's `Origin` and sends `Access-Control-Allow-Credentials: true`. Any site can then make credentialed cross-origin requests and read the responses, exposing cookie-authenticated endpoints to arbitrary origins.\n\n### Details\n\nThe spec forbids `Access-Control-Allow-Origin: *` with credentials and browsers reject it, so this configuration used to fail closed. In affected versions the middleware reflects the request `Origin` instead, so it now succeeds for every origin, including `null`. The preflight also echoes the requested headers back, approving non-simple credentialed requests too.\n\nThis issue arises when an application enables `credentials: true` and leaves `origin` unset or set to the wildcard.\n\n### Impact\n\nAny third-party page a logged-in user visits can read the application's cookie-authenticated endpoints and perform credentialed state-changing requests. This affects applications that enable credentialed CORS without restricting `origin`.","aliases":["CVE-2026-54290"],"modified":"2026-09-10T03:50:48.939674527Z","published":"2026-06-16T14:15:39Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-06-16T14:15:39Z","nvd_published_at":"2026-06-22T18:16:47Z","cwe_ids":["CWE-942"]},"references":[{"type":"WEB","url":"https://github.com/honojs/hono/security/advisories/GHSA-88fw-hqm2-52qc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54290"},{"type":"PACKAGE","url":"https://github.com/honojs/hono"}],"affected":[{"package":{"name":"hono","ecosystem":"npm","purl":"pkg:npm/hono"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.12.25"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-88fw-hqm2-52qc/GHSA-88fw-hqm2-52qc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"}]}