CVE-2026-69207 with a CVSS score of 5.3 is a vulnerability affecting hono versions < 4.12.34 in the hono/cors middleware, allowing an unauthenticated attacker to send preflight requests that consume disproportionate CPU relative to their size, degrading or denying service via the environment template management API, specifically in the rating block's custom icon rendering component; this is a denial-of-service issue only, it does not expose or modify data, and applications using cors with the default (or an empty) allowHeaders are affected, including those that set a non-empty allowHeaders do not reach the affected path, as long headers can block request processing for a noticeable amount of time on runtimes that share one execution thread across requests, stalling concurrent requests as well.
We recommend you to update hono to version 4.13.0 or later.[/subscribe_to_unlock_form]
CVE-2026-69207 with a CVSS score of 5.3 is a vulnerability affecting hono versions < 4.12.34 in the hono/cors middleware, allowing an unauthenticated attacker to send preflight requests that consume disproportionate CPU relative to their size, degrading or denying service via the environment template management API, specifically in the rating block's custom icon rendering component; this is a denial-of-service issue only, it does not expose or modify data, and applications using cors with the default (or an empty) allowHeaders are affected, including those that set a non-empty allowHeaders do not reach the affected path, as long headers can block request processing for a noticeable amount of time on runtimes that share one execution thread across requests, stalling concurrent requests as well.
We recommend you to update hono to version 4.13.0 or later.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]