Home

Description

hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers can craft specially crafted attribute keys containing characters like quotes or angle brackets to break html tag boundaries and inject arbitrary attributes or elements.

PUBLISHED Reserved 2026-06-22 | Published 2026-06-24 | Updated 2026-06-24 | Assigner VulnCheck




MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Problem types

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

Default status
unaffected

Any version before 4.12.14
affected

4.12.14 (semver)
unaffected

Credits

tndud042713 reporter

References

github.com/...s/hono/security/advisories/GHSA-458j-xx4x-4375 (GitHub Security Advisory (GHSA-458j-xx4x-4375)) vendor-advisory

www.vulncheck.com/...oper-jsx-attribute-name-handling-in-ssr (VulnCheck Advisory: hono - HTML Injection via Improper JSX Attribute Name Handling in SSR) third-party-advisory

cve.org (CVE-2026-56761)

nvd.nist.gov (CVE-2026-56761)

Download JSON