Threat Advisory

Hono Algorithmic Complexity DoS in Language Middleware

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting hono versions >= 3.8.0, < 4.12.34 affecting hono versions >= 4.12.0, < 4.12.34 affecting hono versions >= 4.7.0, < 4.12.34 have been identified in hono, a product used for language middleware and proxy helper functionality. The overall risk/impact is significant as the affected versions are vulnerable to algorithmic complexity denial of service.

CVE-2026-71848 (CVSS 5.3 — Severity): The languageDetector middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen-separated subtags.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting hono versions >= 3.8.0, < 4.12.34 affecting hono versions >= 4.12.0, < 4.12.34 affecting hono versions >= 4.7.0, < 4.12.34 have been identified in hono, a product used for language middleware and proxy helper functionality. The overall risk/impact is significant as the affected versions are vulnerable to algorithmic complexity denial of service.

CVE-2026-71848 (CVSS 5.3 — Severity): The languageDetector middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen-separated subtags.[emaillocker id="1283"]

CVE-2026-71849 (CVSS 3.7 — Severity): The Proxy Helper does not remove response headers listed in the origin's Connection header, which may lead to disclosure of connection-scoped or internal metadata contained in such headers.

CVE-2026-71850 (CVSS 4.8 — Severity): An insecure direct object reference vulnerability exists in the proxy helper, allowing an attacker to access sensitive information by manipulating the request. These vulnerabilities collectively present a significant risk to applications using hono for language middleware and proxy helper functionality. Administrators should review their exposure and apply updates to affected versions of hono. These vulnerabilities collectively present a significant risk to applications using hono for language middleware and proxy helper functionality.

These vulnerabilities collectively present a significant risk to applications using hono for language middleware and proxy helper functionality.

RECOMMENDATION:

We recommend you to update Hono to version 4.12.34.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu