GHSA-hvrm-45r6-mjfj

    Dashboard / Vulnerabilities / GHSA-hvrm-45r6-mjfj

    GHSA-hvrm-45r6-mjfj

    Published: 21 Jul 2026Last Modified: 10 Sept 2026

    Summary: hono/jsx does not isolate context per request, leading to cross-request data disclosure

    Details: ### Summary `hono/jsx` did not isolate context values per request during server-side rendering. While an async component was suspended on `await`, its provided context value stayed observable to other requests rendering concurrently, so `useContext()` could return a value from a different in-flight request. ### Details During server-side rendering, context values were kept in a process-wide structure rather than scoped to each request's render. While an async component awaited, another request entering the same provider could observe or replace the value; when the first render resumed, it could read the other request's context. This affects the usual ways request-scoped data is passed through a server-rendered JSX tree: - `createContext()` / `useContext()` - the `jsxRenderer` middleware and `useRequestContext()` It arises only when context is read after an `await` inside an async component while requests render concurrently. Reading context synchronously (before any `await`), purely synchronous rendering, and client-side (DOM) rendering are not affected. ### Impact Under concurrent requests, a response could be rendered with another request's context. A user may receive HTML rendered for a different user, and an authorization check performed after an `await` may be evaluated against another user's data. This may lead to: - disclosure of rendered output intended for another user - authorization decisions made with the wrong request's context - cross-request mixing of session or other request-scoped state

    Affected packages

    Package

    Name: hono

    Purl: pkg:npm/hono

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 4.11.8
    Fixed -4.12.27

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-hvrm-45r6-mjfj | CVE-DB