{"id":"GHSA-f577-qrjj-4474","summary":"Hono: JWT middleware accepts any Authorization scheme, not only Bearer","details":"### Summary\n\nThe `jwt` and `jwk` middlewares do not verify that the `Authorization` header value uses the`Bearer` scheme. Any two-part header value — regardless of the scheme name in the first position — proceeds to JWT verification. A request presenting a valid JWT under a non-`Bearer` scheme identifier (such as `Basic` or `Token`) is authenticated identically to a correctly formed `Bearer` request.\n\n### Details\n\nWhen processing an `Authorization` (or custom) header, the middleware splits the value on whitespace and uses the second token as the JWT to verify. It does not check that the first token is `bearer` (case-insensitively). RFC 6750 specifies that JWT bearer tokens must be presented using the `Bearer` scheme; other scheme identifiers carry distinct semantics and may be subject to different policies in network-layer security controls.\n\nThis discrepancy means that scheme-aware external controls — such as WAF rules, API gateways, or reverse proxies that apply policies specific to the `Bearer` scheme identifier — can be bypassed by presenting a valid JWT under a different scheme name.\n\nThis issue affects `hono/jwt` and `hono/jwk` middleware.\n\n### Impact\n\nAn attacker who possesses a valid JWT may present it under a non-`Bearer` scheme identifier and still pass middleware authentication.\n\nThis may lead to:\n\n- Bypass of network-layer security controls that inspect or filter requests based on the authorization scheme identifier\n- Token reuse across authentication schemes in applications that use multiple authorization mechanisms\n\nThis issue affects applications where `hono/jwt` or `hono/jwk` authentication is combined with external controls that enforce scheme-based access policies.","aliases":["CVE-2026-47673"],"modified":"2026-07-17T21:10:03.571679287Z","published":"2026-06-04T17:52:04Z","database_specific":{"cwe_ids":["CWE-285"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-04T17:52:04Z","nvd_published_at":"2026-05-28T17:16:32Z"},"references":[{"type":"WEB","url":"https://github.com/honojs/hono/security/advisories/GHSA-f577-qrjj-4474"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47673"},{"type":"WEB","url":"https://github.com/honojs/hono/commit/5463db2735476959b8af67756f4e513f4fe19115"},{"type":"PACKAGE","url":"https://github.com/honojs/hono"},{"type":"WEB","url":"https://github.com/honojs/hono/releases/tag/v4.12.21"}],"affected":[{"package":{"name":"hono","ecosystem":"npm","purl":"pkg:npm/hono"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.12.21"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-f577-qrjj-4474/GHSA-f577-qrjj-4474.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}