CVE-2026-81888CWE-1275CWE-352csrf

CVE-2026-81888

Medium · published September 1, 2026

CVSS v3.1
5.4
EPSS
0%
Percentile
4.4
In the wild
Unconfirmed
What it is

@hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is absent on both sides, so the anti-CSRF check passes for a callback that never came from a genuine login attempt. This defeats the `state`-based CSRF protection under default usage. Version 0.8.6 has a patch.

The record
Technical detail
CVSS v3.1
5.4 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00149 · 4.4th percentile
Weaknesses
CWE-1275 · Sensitive Cookie with Improper SameSite Attribute; CWE-352 · Cross-Site Request Forgery (CSRF)
Published
2026-09-01T01:17Z
References (4)
EPSS history
Timeline
  • 02 SEP 03:39Z
    EPSS moved — → 0%
    epss
  • 31 AUG 20:27Z
    @hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking
    cvelistv5