CVE-2026-56763: Hono

Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field names to create objects with __proto__ properties. When parsed results are merged into regular JavaScript objects using unsafe merge patterns, attackers can exploit this to achieve prototype pollution and modify object behavior.

Affected products

  • Hono Hono: before 4.12.7 (fixed in 4.12.7)

Published 2026-07-11. Last modified 2026-07-14.