Answer in brief
CVE-2026-56763 records a Medium severity (CVSS 4.8) vulnerability in Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true }). The current sources do not mark it as known exploited. The current feed maps hono (npm). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 4.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps hono (npm). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| hononpm | <4.12.7 | 4.12.7 |
Published upstream
Mar 11, 2026
Evidence: source:ghsa:source_dates:source-dates:recordSource modified
Oct 2, 2026
Evidence: source:ghsa:source_dates:source-dates:recordFirst seen by HOL
Jul 13, 2026
## Summary When using `parseBody({ dot: true })` in HonoRequest, specially crafted form field names such as `__proto__.x` could create objects containing a `__proto__` property. If the parsed result is later merged into regular JavaScript objects using unsafe merge patterns, this may lead to prototype pollution in the target object. ## Details The `parseBody({ dot: true })` feature supports dot notation to construct nested objects from form field names. In previous versions, the `__proto__` path segment was not filtered. As a result, specially crafted keys such as `__proto__.x` could produce objects containing `__proto__` properties. While this behavior does not directly modify `Object.prototype` within Hono itself, it may become exploitable if the parsed result is later merged into regular JavaScript objects using unsafe merge patterns. ## Impact Applications that merge parsed form data into regular objects using unsafe patterns (for example recursive deep merge utilities) may become vulnerable to prototype pollution.
Quoted source text, attributed separately from HOL analysis.