Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fm3f-ch8h-qw8q | @hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking |
Tue, 01 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Honojs
Honojs @hono/oauth-providers |
|
| Vendors & Products |
Honojs
Honojs @hono/oauth-providers |
Mon, 31 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | @hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is absent on both sides, so the anti-CSRF check passes for a callback that never came from a genuine login attempt. This defeats the `state`-based CSRF protection under default usage. Version 0.8.6 has a patch. | |
| Title | @hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking | |
| Weaknesses | CWE-1275 CWE-352 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-01T14:59:01.902Z
Reserved: 2026-08-27T17:48:42.123Z
Link: CVE-2026-81888
No data.
Status : Received
Published: 2026-08-31T21:17:52.317
Modified: 2026-09-01T15:17:31.113
Link: CVE-2026-81888
No data.
OpenCVE Enrichment
Updated: 2026-09-01T14:16:30Z
Github GHSA