CVE-2026-44457: Hono

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware does not skip caching for responses that declare per-user variance via Vary: Authorization or Vary: Cookie. As a result, a response cached for one authenticated user may be served to subsequent requests from different users. This vulnerability is fixed in 4.12.18.

Affected products

  • Hono Hono: before 4.12.18 (fixed in 4.12.18)

Published 2026-05-13. Last modified 2026-06-17.