Threat Advisory

Hono API Gateway Drops Request Header Value During De-Duplication

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in hono, a package affected by three advisories. The overall risk/impact is moderate to high due to potential exposure of sensitive data and server-side attacks. Affected version range is 4.12.27.

CVE-2026-59897: Hono's API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication, allowing an attacker to bypass security controls. An attacker with network access can exploit this vulnerability.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in hono, a package affected by three advisories. The overall risk/impact is moderate to high due to potential exposure of sensitive data and server-side attacks. Affected version range is 4.12.27.

CVE-2026-59897: Hono's API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication, allowing an attacker to bypass security controls. An attacker with network access can exploit this vulnerability.[emaillocker id="1283"]

CVE-2026-59895: Hono's Server-Side XSS via JSX Escaping Bypass in cx Utility allows an attacker to inject malicious code into the application. An attacker with user interaction can exploit this vulnerability.

CVE-2026-59896: hono/jsx does not isolate context. An attacker with network access can exploit this vulnerability.

These vulnerabilities collectively present a significant risk of sensitive data exposure and server-side attacks.

RECOMMENDATION:

We recommend you to update hono to the 4.12.27 version.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu