AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2025-71381.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 02, 2026

Disclosure summary

### Summary A flaw in the CORS middleware allowed request `Vary` headers to be reflected into the response, enabling attacker-controlled `Vary` values and potentially affecting cache behavior. ### Details The middleware previously copied the `Vary` header from the request when `origin` was not set to `"*"`. Since `Vary` is a response header that should only be managed by the server, this could allow an attacker to influence caching behavior or cause inconsistent CORS handling. Most environments will see impact only when shared caches or proxies rely on the `Vary` header. The practical effect varies by configuration. ### Impact May cause cache key pollution and inconsistent CORS enforcement in certain setups. No direct confidentiality, integrity, or availability impact in default configurations. ### Resolution Update to the latest patched release. The CORS middleware has been corrected to handle `Vary` exclusively as a response header.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-q7jf-gf43-6x6p

Open original source · Updated Oct 02, 2026

Hono vulnerable to Vary Header Injection leading to potential CORS Bypass

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
npmhono< 4.10.34.10.3

Original records & references

PUBLISHED 2025-10-24T15:15:13-04:00
MODIFIED 2026-10-02T14:28:56-04:00
INGESTED 2026-10-06T11:45:17-04:00