CVE-2026-47675: Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection
Summary
The serialize() function in hono/cookie validates domain and path options against characters that corrupt Set-Cookie header syntax (;, \r, \n), but does not apply the same validation to sameSite and priority. An application that passes user-controlled input into either option may produce a Set-Cookie response header containing attacker-chosen additional attributes.
Details
When constructing a Set-Cookie header value, serialize() appends the sameSite and priority option values directly into the output string after a presentation-only transformation (capitalizing the first character). Although the TypeScript type signature constrains these options to specific string literals, that constraint is not enforced at runtime; any string value, including one containing ; or line-feed characters, passes through unchanged.
The validation guard that rejects ;, \r, and \n from domain and path is not applied to sameSite or priority. An application that passes a request-derived value to either option therefore provides an injection point into the header line.
This issue arises when an application passes user-controlled input to the sameSite or priority option of setCookie() or serialize().
Impact
An attacker who can control the sameSite or priority option value may inject additional attributes into a Set-Cookie response header.
This may lead to:
- Cookie attribute injection — overriding Domain, Path, HttpOnly, Secure, or Max-Age for the affected cookie - HTTP response header injection on runtimes that do not strictly validate header values, enabling a second attacker-controlled Set-Cookie header in the same response
This issue affects applications that pass user-derived input into the sameSite or priority option of hono/cookie serialization functions.
Other sources
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path options against characters that corrupt Set-Cookie header syntax (;, \r, \n), but does not apply the same validation to sameSite and priority. An application that passes user-controlled input into either option may produce a Set-Cookie response header containing attacker-chosen additional attributes. This vulnerability is fixed in 4.12.21.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/honoto a version that resolves this vulnerability.Fixed in 4.12.21 - Configuration
Ensure the application does not pass user-derived input to the sameSite or priority options. Validate or sanitize these option values before calling setCookie() or serialize() — specifically reject or escape the characters ';', CR ('\r'), and LF ('\n'), or use fixed/whitelisted values.
hono/cookie (serialize/setCookie options) sameSite, priority = reject characters ";", "\r", and "\n"; do not accept user-controlled values - Operational
Audit application code for any call sites that pass user-controlled input into the sameSite or priority options of setCookie() or serialize(), update those sites to use validated or fixed values, and verify Set-Cookie response headers no longer contain injected attributes.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47675?
CVE-2026-47675 has a medium severity rating of 5.3.
How do I fix CVE-2026-47675?
To fix CVE-2026-47675, upgrade to Hono version 4.12.21 or later.
What impact does CVE-2026-47675 have on my application?
CVE-2026-47675 could allow attackers to perform Set-Cookie injection due to improper sanitization.
Who is affected by CVE-2026-47675?
Applications using versions of Hono prior to 4.12.21 are affected by CVE-2026-47675.
What type of attack does CVE-2026-47675 enable?
CVE-2026-47675 enables potential Set-Cookie injection attacks due to lack of validation.