Skip to content

fix(deps): update dependency @hono/oauth-providers to ^0.8.6 [security] - #29

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-hono-oauth-providers-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-hono-oauth-providers-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@hono/oauth-providers (source) ^0.6.2 → ^0.8.6 age confidence

@​hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking

CVE-2026-81888 / GHSA-fm3f-ch8h-qw8q

More information

Details

Summary

The built-in social login providers accept an OAuth callback even when the state value is absent on both sides, so the anti-CSRF check passes for a callback that never came from a genuine login attempt. This defeats the state-based CSRF protection under default usage.

Details

The state check treated two absent values as a match, so a callback that omits state — and for which no state was ever stored — was allowed to redeem the authorization code. Hono's csrf() middleware does not help: it only inspects form-style requests, while the OAuth callback is a top-level GET navigation it treats as safe.

This affects the google, github, facebook, discord, twitch, linkedin, and msentra providers. The x (Twitter) provider is not exploitable due to its PKCE binding.

Impact

An attacker can make a victim's browser complete an OAuth callback that binds the attacker's identity instead of the victim's, leading to login CSRF (the victim silently acts inside the attacker's account) or forced account linking (the attacker's identity is linked to the victim's account, enabling later sign-in as the victim). Affects applications using an affected provider on @hono/oauth-providers 0.8.5 or earlier.

Severity

  • CVSS Score: 5.4 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

honojs/middleware (@​hono/oauth-providers)

v0.8.6

Compare Source

Patch Changes

v0.8.5

Compare Source

Patch Changes
  • #​1404 fce74aeda2958faa4d0ed17dfcfe7cbbb74287fa Thanks @​sushichan044! - fix: enable CSRF protection for MSEntra ID authentication

    Fixed a bug where the state parameter was not being passed to the MSEntra AuthFlow constructor. As a result, CSRF protection now properly works for MSEntra ID authentication, ensuring that authentication requests are protected against Cross-Site Request Forgery attacks.

v0.8.4

Compare Source

Patch Changes

v0.8.3

Compare Source

Patch Changes

v0.8.2

Compare Source

Patch Changes

v0.8.1

Compare Source

Patch Changes

v0.8.0

Compare Source

Minor Changes

v0.7.1

Compare Source

Patch Changes

v0.7.0

Compare Source

Minor Changes
  • #​981 e5f383787c2bd47657f67a99074515eab969963b Thanks @​Younis-Ahmed! - These chages introduces a Twitch OAuth provider, expanding the middleware's OAuth offerings. It includes a new middleware for Twitch authentication, a dedicated AuthFlow class, token refreshing/revocation/validation, and comprehensive type definitions. Detailed tests ensure correct behavior and error handling.
    • Twitch OAuth Middleware src/providers/twitch/twitchAuth.ts: Implements the core authentication flow, handling state management, redirects, and context variable setting (token, refresh-token, user-twitch, granted-scopes).

    • AuthFlow Class src/providers/twitch/authFlow.ts: Encapsulates token exchange and user data retrieval, with robust error handling.

    • Token Operations src/providers/twitch/refreshToken.ts: Provides functions for refreshing and revoking tokens.

    • Type Definitions `src/providers/twitch/types.ts: Defines comprehensive types for Twitch API responses.

    • Extensive Testing (test/handlers.ts, test/index.test.ts): Includes unit tests covering redirection, valid code flow, error handling, refresh/revoke token, custom and built-in state scenarios, using a mock server.

    • Validate Token src/providers/twitch/validateToken: That hit /validate endpoint to verify that the access token is still valid for reasons other than token expiring.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/npm-hono-oauth-providers-vulnerability branch from 16d2248 to b7c8fc1 Compare September 2, 2026 22:48
@renovate renovate Bot changed the title fix(deps): update dependency @hono/oauth-providers to ^0.8.6 [security] fix(deps): update dependency @hono/oauth-providers to ^0.9.0 [security] Sep 2, 2026
@renovate renovate Bot changed the title fix(deps): update dependency @hono/oauth-providers to ^0.9.0 [security] fix(deps): update dependency @hono/oauth-providers to ^0.8.6 [security] Sep 3, 2026
@renovate
renovate Bot force-pushed the renovate/npm-hono-oauth-providers-vulnerability branch 2 times, most recently from 82f77db to f21065f Compare September 3, 2026 07:43
@renovate renovate Bot changed the title fix(deps): update dependency @hono/oauth-providers to ^0.8.6 [security] fix(deps): update dependency @hono/oauth-providers to ^0.9.0 [security] Sep 3, 2026
@renovate renovate Bot changed the title fix(deps): update dependency @hono/oauth-providers to ^0.9.0 [security] fix(deps): update dependency @hono/oauth-providers to ^0.8.6 [security] Sep 4, 2026
@renovate
renovate Bot force-pushed the renovate/npm-hono-oauth-providers-vulnerability branch 2 times, most recently from a69e95b to fd562a9 Compare September 7, 2026 23:32
@renovate renovate Bot changed the title fix(deps): update dependency @hono/oauth-providers to ^0.8.6 [security] fix(deps): update dependency @hono/oauth-providers to ^0.9.0 [security] Sep 7, 2026
@renovate
renovate Bot force-pushed the renovate/npm-hono-oauth-providers-vulnerability branch from fd562a9 to afe240a Compare September 8, 2026 04:12
@renovate renovate Bot changed the title fix(deps): update dependency @hono/oauth-providers to ^0.9.0 [security] fix(deps): update dependency @hono/oauth-providers to ^0.8.6 [security] Sep 8, 2026
@renovate
renovate Bot force-pushed the renovate/npm-hono-oauth-providers-vulnerability branch from afe240a to 7172de3 Compare September 9, 2026 20:39
@renovate renovate Bot changed the title fix(deps): update dependency @hono/oauth-providers to ^0.8.6 [security] fix(deps): update dependency @hono/oauth-providers to ^0.9.0 [security] Sep 9, 2026
@renovate
renovate Bot force-pushed the renovate/npm-hono-oauth-providers-vulnerability branch from 7172de3 to 9cfff05 Compare September 10, 2026 03:38
@renovate renovate Bot changed the title fix(deps): update dependency @hono/oauth-providers to ^0.9.0 [security] fix(deps): update dependency @hono/oauth-providers to ^0.8.6 [security] Sep 10, 2026
@renovate
renovate Bot force-pushed the renovate/npm-hono-oauth-providers-vulnerability branch from 9cfff05 to 3298c25 Compare September 10, 2026 15:52
@renovate renovate Bot changed the title fix(deps): update dependency @hono/oauth-providers to ^0.8.6 [security] fix(deps): update dependency @hono/oauth-providers to ^0.9.0 [security] Sep 10, 2026
@renovate
renovate Bot force-pushed the renovate/npm-hono-oauth-providers-vulnerability branch from 3298c25 to 409cbf4 Compare September 10, 2026 22:39
@renovate renovate Bot changed the title fix(deps): update dependency @hono/oauth-providers to ^0.9.0 [security] fix(deps): update dependency @hono/oauth-providers to ^0.8.6 [security] Sep 10, 2026
@renovate
renovate Bot force-pushed the renovate/npm-hono-oauth-providers-vulnerability branch from 409cbf4 to a5264dc Compare September 15, 2026 18:04
@renovate renovate Bot changed the title fix(deps): update dependency @hono/oauth-providers to ^0.8.6 [security] fix(deps): update dependency @hono/oauth-providers to ^0.9.0 [security] Sep 15, 2026
@renovate
renovate Bot force-pushed the renovate/npm-hono-oauth-providers-vulnerability branch from a5264dc to afc6ea1 Compare September 16, 2026 00:52
@renovate renovate Bot changed the title fix(deps): update dependency @hono/oauth-providers to ^0.9.0 [security] fix(deps): update dependency @hono/oauth-providers to ^0.8.6 [security] Sep 16, 2026
@renovate
renovate Bot force-pushed the renovate/npm-hono-oauth-providers-vulnerability branch from afc6ea1 to c9b417c Compare September 20, 2026 08:02
@renovate renovate Bot changed the title fix(deps): update dependency @hono/oauth-providers to ^0.8.6 [security] fix(deps): update dependency @hono/oauth-providers to ^0.9.0 [security] Sep 20, 2026
@renovate
renovate Bot force-pushed the renovate/npm-hono-oauth-providers-vulnerability branch from c9b417c to 563a45f Compare September 20, 2026 09:50
@renovate renovate Bot changed the title fix(deps): update dependency @hono/oauth-providers to ^0.9.0 [security] fix(deps): update dependency @hono/oauth-providers to ^0.8.6 [security] Sep 20, 2026
@renovate
renovate Bot force-pushed the renovate/npm-hono-oauth-providers-vulnerability branch from 563a45f to 9e16a42 Compare September 23, 2026 15:54
@renovate renovate Bot changed the title fix(deps): update dependency @hono/oauth-providers to ^0.8.6 [security] fix(deps): update dependency @hono/oauth-providers to ^0.9.0 [security] Sep 23, 2026
@renovate renovate Bot changed the title fix(deps): update dependency @hono/oauth-providers to ^0.9.0 [security] fix(deps): update dependency @hono/oauth-providers to ^0.8.6 [security] Sep 24, 2026
@renovate
renovate Bot force-pushed the renovate/npm-hono-oauth-providers-vulnerability branch 2 times, most recently from a0fc4bd to fa8b8f0 Compare September 24, 2026 22:55
@renovate renovate Bot changed the title fix(deps): update dependency @hono/oauth-providers to ^0.8.6 [security] fix(deps): update dependency @hono/oauth-providers to ^0.9.0 [security] Sep 24, 2026
@renovate
renovate Bot force-pushed the renovate/npm-hono-oauth-providers-vulnerability branch from fa8b8f0 to 82ece5a Compare September 25, 2026 12:05
@renovate renovate Bot changed the title fix(deps): update dependency @hono/oauth-providers to ^0.9.0 [security] fix(deps): update dependency @hono/oauth-providers to ^0.8.6 [security] Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants