CVE-2026-59896
EUVD-2026-4232608.07.2026, 17:17
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a different in-flight request to be used after an await in an async component. This issue is fixed in version 4.12.27.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hono | hono | 4.11.8 ≤ 𝑥 < 4.12.27 |
𝑥
= Vulnerable software versions