chore(deps): update dependency hono to v4.12.34 [security] - #1189
Closed
renovate[bot] wants to merge 1 commit into
Closed
chore(deps): update dependency hono to v4.12.34 [security]#1189renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
2 times, most recently
from
August 9, 2026 08:55
bec4aba to
18c00e5
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
from
August 9, 2026 08:58
18c00e5 to
e342684
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
from
August 9, 2026 09:13
e342684 to
2c17e09
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
2 times, most recently
from
August 9, 2026 09:29
f42ee27 to
af06ab7
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
from
August 9, 2026 09:34
af06ab7 to
407e45f
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
from
August 9, 2026 13:03
407e45f to
c4b5e4f
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
from
August 9, 2026 13:07
c4b5e4f to
344d5ad
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
from
August 9, 2026 13:18
344d5ad to
d22ae2e
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
from
August 9, 2026 13:21
d22ae2e to
921c3f0
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
from
August 9, 2026 18:03
921c3f0 to
e9d291a
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
from
August 9, 2026 18:08
e9d291a to
7886d57
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
from
August 9, 2026 20:33
7886d57 to
a651907
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
from
August 9, 2026 20:38
a651907 to
21cb7dc
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
from
August 10, 2026 02:01
21cb7dc to
46eff5f
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
from
August 10, 2026 02:13
46eff5f to
b6533d8
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
from
August 10, 2026 05:54
b6533d8 to
7b798ff
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
from
August 10, 2026 05:58
7b798ff to
7ebfd3d
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
from
August 10, 2026 08:44
7ebfd3d to
42bc0b5
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
from
August 10, 2026 08:49
42bc0b5 to
f8cc875
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
from
August 10, 2026 14:50
f8cc875 to
eb5d417
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
from
August 10, 2026 14:55
eb5d417 to
00e1d52
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-vulnerability
branch
from
August 10, 2026 19:04
00e1d52 to
f93d03b
Compare
h4yfans
added a commit
that referenced
this pull request
Aug 12, 2026
…1356) Bundles five stale bot PRs into a single change against current main so one coherent lockfile lands instead of nine conflicting stale ones. - prettier ^3.8.3 -> ^3.9.6 (#1197) - ip-address override >=10.1.1 -> >=10.3.1, resolves 10.5.0 (#1190, security) - hono override >=4.12.27 -> >=4.12.34, resolves 4.13.1 (#1189, security) - nanoid@>=4.0.0 <5.0.9 override 5.0.9 -> 5.1.16 (#1194) - framer-motion -> motion ^12.24.7 in landing (#1196) The renovate PR for the motion swap replaced the package but left all 49 `from 'framer-motion'` imports untouched, which does not resolve once framer-motion is off the manifest. Repointed them at `motion/react` and updated the vite manualChunks entry that named the old package. Left out deliberately: #1193 (nanoid 6.0.0 major) and #1195 (forces a 3.x transitive to v5) — both advisories are already closed by the existing pins, so they add breakage risk without security value.
Collaborator
|
Superseded by #1356 (merged as Verified on main: hono 4.13.1, ip-address 10.5.0, nanoid 5.1.16, prettier 3.9.6, motion 12.34.0. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
>=4.12.27→>=4.12.344.12.33→4.12.34Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
CVE-2026-69207 / GHSA-8j4g-w8fx-2239
More information
Details
Summary
The built-in CORS middleware (
hono/cors) parses the attacker-controlledAccess-Control-Request-Headersrequest header during a preflight (OPTIONS) request using a regular expression whose running time is quadratic in the input length. A single request carrying a long run of whitespace can consume seconds of CPU, and repeated requests can render the service unresponsive. This parsing runs under the default configuration.Details
On a CORS preflight, when
allowHeadersis not configured - the default - the middleware reflects and parses theAccess-Control-Request-Headersvalue. The parser used a whitespace-tolerant regular expression whose backtracking makes the work grow quadratically (O(n²)) with the length of the value when it contains a long whitespace sequence without a delimiter.Because the header value is bounded only by the deployment's maximum HTTP header size, a single preflight can block request processing for a noticeable amount of time; on runtimes that share one execution thread across requests, this stalls concurrent requests as well. No authentication, special origin, or user interaction is required.
This issue arises for any application using
cors()with the default (or an empty)allowHeaders. Applications that set a non-emptyallowHeadersdo not reach the affected path.Impact
An unauthenticated attacker can send preflight requests that each consume disproportionate CPU relative to their size, degrading or denying service. This is a denial-of-service issue only; it does not expose or modify data.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Hono: Algorithmic Complexity DoS in Language Middleware
CVE-2026-71848 / GHSA-54fx-42gc-7vw4
More information
Details
Summary
The
languageDetectormiddleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen-separated subtags.Details
To implement progressive language-tag truncation,
normalizeLanguage()repeatedly callsparts.slice(0, i).join('-')for every possible prefix. The total amount of string processing grows quadratically with the number of subtags.Language values may come from a query parameter, cookie,
Accept-Languageheader, or URL path, depending on the detector configuration. The default detector order enables query-string, cookie, and header detection, so applications usinglanguageDetector()may expose this processing to unauthenticated requests.Request-size limits reduce the maximum cost of a single request but do not eliminate the issue. Inputs accepted by common JavaScript runtimes can still cause noticeable synchronous event-loop blocking.
Impact
An attacker may repeatedly send requests containing long, hyphen-separated language tags, causing excessive CPU consumption and preventing unrelated requests from being processed.
The practical impact depends on the runtime's request-size limits, reverse-proxy configuration, and the detectors enabled by the application.
Resolution
The progressive lookup should avoid reconstructing every shorter prefix. The implementation can instead inspect the configured supported languages and select the longest value that matches the input at a hyphen boundary.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Hono: Proxy Helper does not remove response headers listed in the
ConnectionheaderCVE-2026-71849 / GHSA-79qm-7rj5-m7r9
More information
Details
Summary
The Proxy Helper (
hono/proxy) does not remove response headers named by the origin'sConnectionheader. Headers that the origin marked as connection-scoped are therefore forwarded to clients.Details
Per RFC 9110 Section 7.6.1, an intermediary must remove the header fields listed in a message's
Connectionheader field before forwarding the message, in addition to the well-known hop-by-hop headers. Theproxy()function removed the well-known hop-by-hop headers (includingConnectionitself) from origin responses, but did not remove the headers that the response'sConnectionheader field designated as connection-scoped.This issue arises when an application proxies responses from an origin that declares additional, non-standard headers as hop-by-hop via the
Connectionresponse header.Impact
A client may receive response headers that the origin intended only for its immediate peer. This may lead to:
This issue affects applications that use the Proxy Helper (
hono/proxy) to forward responses from origins that list custom header names in theirConnectionresponse header. Applications whose origins only use the standard hop-by-hop headers are not affected.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Hono:
memo()retains SSR output across requests, leading to cross-user data disclosureCVE-2026-71850 / GHSA-f23p-vx2j-j53r
More information
Details
Summary
memo()fromhono/jsxretains the result of a server-side render and reuses it for later renders with comparator-equal props. Request-scoped values read inside the component take no part in that comparison, so a response can contain HTML rendered for another user's request.Details
Components wrapped with
memo()are compared by props alone. Values read implicitly during rendering do not participate: JSX Context throughcreateContext()anduseContext(),useRequestContext()fromhono/jsx-renderer, andgetContext()fromhono/context-storage. The retained result lives as long as the wrapped component, so it outlives the request that produced it.Per-request context isolation is not what fails: the current request's values are established correctly, but the memoized component is skipped before anything reads them.
This issue arises when a component wrapped in
memo()obtains user- or request-specific data from an ambient context instead of through props.Impact
A user may receive a response containing HTML rendered for another user, when both render the same memoized component with comparator-equal props on the same warm instance.
This may lead to:
Exploitation depends on the order in which renders populate the retained value and on both requests reaching the same warm instance.
This issue affects applications that render with
hono/jsxon the server and wrap a component reading ambient request state inmemo(). Applications that pass all request-specific values through props, or that do not usememo(), are unaffected. Client-side rendering is unaffected.Severity
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
honojs/hono (hono)
v4.12.34Compare Source
v4.12.33Compare Source
What's Changed
@hono/node-serverin #5167Full Changelog: honojs/hono@v4.12.32...v4.12.33
v4.12.32Compare Source
What's Changed
Object.create(null)when parsing query, headers, and params in #5161Full Changelog: honojs/hono@v4.12.31...v4.12.32
v4.12.31Compare Source
v4.12.30Compare Source
What's Changed
Full Changelog: honojs/hono@v4.12.29...v4.12.30
v4.12.29Compare Source
What's Changed
compatibilityDateby @yusukebe in #5100*as a match by @yusukebe in #5084New Contributors
Full Changelog: honojs/hono@v4.12.28...v4.12.29
v4.12.28Compare Source
What's Changed
*.tsbuildinfoby @yusukebe in #5066devDependenciesby @yusukebe in #5085New Contributors
Full Changelog: honojs/hono@v4.12.27...v4.12.28
Configuration
📅 Schedule: (in timezone UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.