{"id":"GHSA-j6c9-x7qj-28xf","summary":"hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice","details":"### Summary\n\nOn AWS Lambda, the ALB single-header response and the VPC Lattice v2 response join multiple `Set-Cookie` headers into one comma-separated value. Because commas also appear inside cookie attributes (for example `Expires` dates), clients cannot split the value back into individual cookies and silently drop or misparse them.\n\n### Details\n\nPer RFC 6265, each cookie must be its own `Set-Cookie` header line, and commas may appear inside attribute values. Joining cookies with `\", \"` collides with those commas, producing a value that clients cannot reliably split. Only ALB single-header mode and VPC Lattice v2 are affected; API Gateway v1/v2 and ALB with multi-value headers enabled already use an array and are unaffected.\n\n### Impact\n\nA client may receive only one of the cookies, a malformed cookie, or none. Session, CSRF, or preference cookies can silently fail to apply, breaking sessions or forcing re-authentication. This affects applications that set multiple cookies per response and run on AWS Lambda behind an ALB in single-header mode (the default) or VPC Lattice v2.","aliases":["CVE-2026-54287"],"modified":"2026-07-21T17:01:15.140218600Z","published":"2026-06-16T14:08:40Z","database_specific":{"nvd_published_at":"2026-06-22T18:16:47Z","cwe_ids":["CWE-116"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-16T14:08:40Z"},"references":[{"type":"WEB","url":"https://github.com/honojs/hono/security/advisories/GHSA-j6c9-x7qj-28xf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54287"},{"type":"PACKAGE","url":"https://github.com/honojs/hono"}],"affected":[{"package":{"name":"hono","ecosystem":"npm","purl":"pkg:npm/hono"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.12.25"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-j6c9-x7qj-28xf/GHSA-j6c9-x7qj-28xf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}