Skip to content

Update npm package hono to v4.13.5 [SECURITY] - #442

Open
hash-dependencies[bot] wants to merge 1 commit into
mainfrom
deps/js/npm-hono-vulnerability
Open

hash-dependencies[bot] wants to merge 1 commit into
mainfrom
deps/js/npm-hono-vulnerability

Conversation

@hash-dependencies

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
hono (source) 4.13.24.13.5 age confidence

Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials

CVE-2026-84363 / GHSA-crvj-82cr-hjcx

More information

Details

Summary

Hono's query parsing does not stop at the URL fragment: a ? appearing after a # is treated as the start of a query string. As a result, the application can read request parameters that no other component involved in handling the request can see.

Details

A fragment is never part of the query, and every standard URL consumer — browsers, new URL(), reverse proxies — ignores everything from the first # onward. Hono's routing followed that rule; its query helpers did not.

For one and the same request, this produces an interpretation differential:

  • A component in front of the application that inspects the query string — filtering rules, parameter allow/deny lists, access logging — observes no parameters, while the application reads and acts on them.
  • The cache middleware removed the fragment when building its cache key, so a response influenced by parameters carried inside the fragment could be stored under a key that did not reflect them and later returned to other users.

The same divergence reaches request validation and any middleware that reads query parameters.

This requires a request target containing a literal # to reach the application. Deployments on runtimes that normalise such a target — including Cloudflare Workers — are not affected, and neither are those behind an intermediary that strips the fragment.

Impact

An attacker can cause the application to act on parameters that components in front of it never observe.

This may lead to:

  • filtering rules, allow/deny lists, and audit logging being blind to parameters the application still processes
  • a cached response being stored under a key that does not reflect the parameters used to produce it, and served to other users
  • stored cross-site scripting, where such a parameter is reflected into a cached HTML response without escaping

This issue affects applications that read query parameters and run on a runtime that passes a literal # through to the request URL.

Severity

  • CVSS Score: 5.9 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Hono: Incomplete fix for CVE-2026-39408: toSSG() still writes files outside the output directory

CVE-2026-84365 / GHSA-gqvv-2mrq-wpjv

More information

Details

Summary

The fix released for CVE-2026-39408 does not cover every traversal sequence. toSSG() can still write files outside the configured output directory when a route parameter contains consecutive parent-directory segments.

Details

Static site generation builds each output path from the route path and the values supplied through ssgParams, then verifies that the result stays inside the output directory. That check normalizes the path with the same routine that built it, and the routine did not fully collapse runs of consecutive parent-directory segments. A value carrying enough of them produces a path the check accepts, but the filesystem resolves outside the output directory.

The earlier fix handled a single parent-directory segment, so it blocks the sequence reported at the time while leaving longer runs unhandled. The check also treated output directories that differ only in how they are rooted as equivalent.

This arises when an application generates a static site from route parameter values it does not fully control — slugs coming from a CMS, an API, or user submissions.

Impact

A value reaching ssgParams from an untrusted source can cause build output to be written outside the intended output directory, carrying whatever content the route handler produced.

This may lead to:

  • files being created or overwritten elsewhere in the build environment
  • generated artifacts or deployment output being altered

This affects build-time static site generation only; request-time routing is not affected. Applications whose ssgParams values are entirely developer-controlled are not affected.

Severity

  • CVSS Score: 6.5 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

honojs/hono (hono)

v4.13.5

Compare Source

Security fixes

This release includes fixes for the following security issues:

Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials

Affects: Cache Middleware and applications behind a proxy, WAF, or logging layer that inspects query strings. Fixes query parsing that did not stop at the URL fragment, so a ? after a # was treated as the start of a query string and the application could read parameters that the other component never saw. GHSA-crvj-82cr-hjcx

Incomplete fix for CVE-2026-39408: toSSG() still writes files outside the output directory

Affects: toSSG() for Static Site Generation. Fixes a path normalization gap where consecutive parent-directory segments in ssgParams values were not fully collapsed, bypassing the containment check added in 4.12.12. GHSA-gqvv-2mrq-wpjv

Unbounded dot-notation nesting in parseBody() can cause memory exhaustion

Affects: parseBody() when dot-notation parsing is enabled. Fixes unbounded expansion of dot-separated field names, where a small request body could allocate a disproportionately large object graph and concurrent requests could exhaust the heap. GHSA-g6gw-c38x-mqfc


Users who use Cache Middleware, deploy behind a proxy or WAF that inspects query strings, use Static Site Generation, or use parseBody({ dot: true }) are strongly encouraged to upgrade to this version.

v4.13.4

Compare Source

What's Changed

  • fix(request): handle params on unmatched requests in #​5268
  • fix(jsx/dom): execute previous ref cleanup when ref prop changes on re-render in #​5264
  • fix(reg-exp-router): associate wildcard middleware with matching routes in #​5266
  • perf(router): share null object creation in #​5267
  • fix(etag): match If-None-Match tags with optional whitespace before the comma in #​5222
  • fix(client): skip undefined header and cookie values in #​5244
  • fix(client): skip an undefined entry inside a query array in #​5272
  • fix(client): skip an undefined entry inside a form array in #​5280
  • fix(client): support custom buildSearchParams and filter undefined query in $ws() bin #​5256
  • fix(accepts): support wildcard media types and specificity ordering in defaultMatch in #​5255
  • fix(client): omit empty query delimiter in #​5283
  • fix(request): drop stale content length for cloned FormData in #​5282
  • fix(request): serialize cached JSON body in cloneRawRequest in #​5288
  • fix(cookie): allow parsing signed cookies with empty string values in #​5246
  • fix(utils/stream): do not let abort listeners crash abort() in #​5274

Full Changelog: honojs/hono@v4.13.3...v4.13.4

v4.13.3

Compare Source

What's Changed

  • fix(client): prevent URL corruption when replaceUrlParam contains $ replacement tokens in #​5227
  • fix(etag): copy pending stream bytes in #​5239
  • fix(etag): avoid skipping headers when filtering 304 response headers in #​5234
  • fix(cors): append Origin to Vary header on OPTIONS preflight in #​5235
  • docs(context): add custom headers append option example to Context JSDoc in #​5248
  • fix(trie-router): match suffix wildcard routes in #​5236
  • fix(pattern-router/linear-router): prevent prefix overmatch on wildcard routes in #​5252
  • fix(csrf): exempt OPTIONS request from CSRF validation in #​5250
  • fix(utils/ipaddr): avoid truncation on embedded IPv4 addresses in expand IPv6 in #​5247
  • feat(pretty-json): support structured JSON content-types (+json) in #​5226

Full Changelog: honojs/hono@v4.13.2...v4.13.3


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • "before 4am every weekday,every weekend"

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@cursor

cursor Bot commented Sep 10, 2026

Copy link
Copy Markdown

PR Summary

Low Risk
Only dependency version pins change; risk is low for the PR itself while it reduces exposure to known Hono CVEs in transitive usage.

Overview
Bumps the pinned hono version from 4.13.2 to 4.13.5 via package.json overrides and the matching package-lock.json entry, so the whole dependency tree resolves to the patched release.

This is a security-driven patch upgrade (Renovate) addressing Hono advisories including query parsing past URL fragments (cache/proxy interpretation issues), improved toSSG() path containment, and bounded parseBody() dot-notation nesting—without any changes to app or server source in this diff.

Reviewed by Cursor Bugbot for commit ab72239. Bugbot is set up for automated code reviews on this repo. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants