Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59896

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a different in-flight request to be used after an await in an async component. This issue is fixed in version 4.12.27.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hono:hono:*:*:*:*:*:node.js:*:*
Версия от 4.11.8 (включая) до 4.12.27 (исключая)

EPSS

Процентиль: 9%
0.00191
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 6.5
redhat
26 дней назад

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a different in-flight request to be used after an await in an async component. This issue is fixed in version 4.12.27.

CVSS3: 6.5
github
13 дней назад

hono/jsx does not isolate context per request, leading to cross-request data disclosure

EPSS

Процентиль: 9%
0.00191
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-362