fix(deps): update dependency @hono/oauth-providers to ^0.8.6 [security] - #29
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/npm-hono-oauth-providers-vulnerability
branch
from
September 2, 2026 22:48
16d2248 to
b7c8fc1
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-oauth-providers-vulnerability
branch
2 times, most recently
from
September 3, 2026 07:43
82f77db to
f21065f
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-oauth-providers-vulnerability
branch
2 times, most recently
from
September 7, 2026 23:32
a69e95b to
fd562a9
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-oauth-providers-vulnerability
branch
from
September 8, 2026 04:12
fd562a9 to
afe240a
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-oauth-providers-vulnerability
branch
from
September 9, 2026 20:39
afe240a to
7172de3
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-oauth-providers-vulnerability
branch
from
September 10, 2026 03:38
7172de3 to
9cfff05
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-oauth-providers-vulnerability
branch
from
September 10, 2026 15:52
9cfff05 to
3298c25
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-oauth-providers-vulnerability
branch
from
September 10, 2026 22:39
3298c25 to
409cbf4
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-oauth-providers-vulnerability
branch
from
September 15, 2026 18:04
409cbf4 to
a5264dc
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-oauth-providers-vulnerability
branch
from
September 16, 2026 00:52
a5264dc to
afc6ea1
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-oauth-providers-vulnerability
branch
from
September 20, 2026 08:02
afc6ea1 to
c9b417c
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-oauth-providers-vulnerability
branch
from
September 20, 2026 09:50
c9b417c to
563a45f
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-oauth-providers-vulnerability
branch
from
September 23, 2026 15:54
563a45f to
9e16a42
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-oauth-providers-vulnerability
branch
2 times, most recently
from
September 24, 2026 22:55
a0fc4bd to
fa8b8f0
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-oauth-providers-vulnerability
branch
from
September 25, 2026 12:05
fa8b8f0 to
82ece5a
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.6.2→^0.8.6@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking
CVE-2026-81888 / GHSA-fm3f-ch8h-qw8q
More information
Details
Summary
The built-in social login providers accept an OAuth callback even when the
statevalue is absent on both sides, so the anti-CSRF check passes for a callback that never came from a genuine login attempt. This defeats thestate-based CSRF protection under default usage.Details
The
statecheck treated two absent values as a match, so a callback that omitsstate— and for which nostatewas ever stored — was allowed to redeem the authorization code. Hono'scsrf()middleware does not help: it only inspects form-style requests, while the OAuth callback is a top-levelGETnavigation it treats as safe.This affects the
google,github,facebook,discord,twitch,linkedin, andmsentraproviders. Thex(Twitter) provider is not exploitable due to its PKCE binding.Impact
An attacker can make a victim's browser complete an OAuth callback that binds the attacker's identity instead of the victim's, leading to login CSRF (the victim silently acts inside the attacker's account) or forced account linking (the attacker's identity is linked to the victim's account, enabling later sign-in as the victim). Affects applications using an affected provider on
@hono/oauth-providers0.8.5or earlier.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
honojs/middleware (@hono/oauth-providers)
v0.8.6Compare Source
Patch Changes
b37765f40b7bddb1d8fce39573b085222dea58c1Thanks @yusukebe! - fix: fail closed on missing OAuth state to prevent login CSRFv0.8.5Compare Source
Patch Changes
#1404
fce74aeda2958faa4d0ed17dfcfe7cbbb74287faThanks @sushichan044! - fix: enable CSRF protection for MSEntra ID authenticationFixed a bug where the state parameter was not being passed to the MSEntra AuthFlow constructor. As a result, CSRF protection now properly works for MSEntra ID authentication, ensuring that authentication requests are protected against Cross-Site Request Forgery attacks.
v0.8.4Compare Source
Patch Changes
1980a66370d4afc8d552ac08bd25af0c87b49112Thanks @mrdear! - fixed github email request content-typev0.8.3Compare Source
Patch Changes
ba19e66f6d086089e15b04bc866c7ebf9cd43409Thanks @rxliuli! - handle refersh_token on googleAuthv0.8.2Compare Source
Patch Changes
e1e8a6626d4a739f40ec1ac97c1671322522bee6Thanks @BarryThePenguin! - Update package repositoryv0.8.1Compare Source
Patch Changes
641fd4c3de6d3248f131a09748f55a9007d7f77cThanks @BarryThePenguin! - Add explicit return typesv0.8.0Compare Source
Minor Changes
cf48336cbd123a45b461caaa41325d2302182901Thanks @BarryThePenguin! - The PR adds Microsoft Entra (AzureAD) to the list of supported 3rd-party OAuth providers.v0.7.1Compare Source
Patch Changes
091b182a6ac1b7bb1129123d3cd0acca5e41b80dThanks @liquidleif! - fix: Update twitter authorization urlv0.7.0Compare Source
Minor Changes
e5f383787c2bd47657f67a99074515eab969963bThanks @Younis-Ahmed! - These chages introduces a Twitch OAuth provider, expanding the middleware's OAuth offerings. It includes a new middleware for Twitch authentication, a dedicatedAuthFlowclass, token refreshing/revocation/validation, and comprehensive type definitions. Detailed tests ensure correct behavior and error handling.Twitch OAuth Middleware
src/providers/twitch/twitchAuth.ts: Implements the core authentication flow, handling state management, redirects, and context variable setting (token,refresh-token,user-twitch,granted-scopes).AuthFlow Class
src/providers/twitch/authFlow.ts: Encapsulates token exchange and user data retrieval, with robust error handling.Token Operations
src/providers/twitch/refreshToken.ts: Provides functions for refreshing and revoking tokens.Type Definitions `src/providers/twitch/types.ts: Defines comprehensive types for Twitch API responses.
Extensive Testing (
test/handlers.ts,test/index.test.ts): Includes unit tests covering redirection, valid code flow, error handling, refresh/revoke token, custom and built-in state scenarios, using a mock server.Validate Token
src/providers/twitch/validateToken: That hit/validateendpoint to verify that the access token is still valid for reasons other than token expiring.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.