CVE-2026-47675Hono · Hono
Vulnerability data via NVD (ingested)
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path options against characters that corrupt Set-Cookie header syntax (;, \r, \n), but does not apply the same validation to sameSite and priority. An application that passes user-controlled input into either option may produce a Set-Cookie response header containing attacker-chosen additional attributes. This vulnerability is fixed in 4.12.21.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-47675product:"Hono Hono"http.html:"Hono"More intel sources (5)
vuln:CVE-2026-47675vulnerabilities.cve_id: CVE-2026-47675CVE-2026-47675CVE-2026-47675"CVE-2026-47675" exploit -site:nvd.nist.gov