Multiple security vulnerabilities have been identified in hono, a package affected by three advisories. The overall risk/impact is moderate to high due to potential exposure of sensitive data and server-side attacks. Affected version range is 4.12.27.
CVE-2026-59897: Hono's API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication, allowing an attacker to bypass security controls. An attacker with network access can exploit this vulnerability.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in hono, a package affected by three advisories. The overall risk/impact is moderate to high due to potential exposure of sensitive data and server-side attacks. Affected version range is 4.12.27.
CVE-2026-59897: Hono's API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication, allowing an attacker to bypass security controls. An attacker with network access can exploit this vulnerability.[emaillocker id="1283"]
CVE-2026-59895: Hono's Server-Side XSS via JSX Escaping Bypass in cx Utility allows an attacker to inject malicious code into the application. An attacker with user interaction can exploit this vulnerability.
CVE-2026-59896: hono/jsx does not isolate context. An attacker with network access can exploit this vulnerability.
These vulnerabilities collectively present a significant risk of sensitive data exposure and server-side attacks.
We recommend you to update hono to the 4.12.27 version.
The following reports contain further technical details:
[/emaillocker]