Update npm package hono to v4.13.5 [SECURITY] - #442
Open
hash-dependencies[bot] wants to merge 1 commit into
Open
hash-dependencies[bot] wants to merge 1 commit into
hash-dependencies[bot] wants to merge 1 commit into
Conversation
PR SummaryLow Risk Overview This is a security-driven patch upgrade (Renovate) addressing Hono advisories including query parsing past URL fragments (cache/proxy interpretation issues), improved Reviewed by Cursor Bugbot for commit ab72239. Bugbot is set up for automated code reviews on this repo. Configure here. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.13.2→4.13.5Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials
CVE-2026-84363 / GHSA-crvj-82cr-hjcx
More information
Details
Summary
Hono's query parsing does not stop at the URL fragment: a
?appearing after a#is treated as the start of a query string. As a result, the application can read request parameters that no other component involved in handling the request can see.Details
A fragment is never part of the query, and every standard URL consumer — browsers,
new URL(), reverse proxies — ignores everything from the first#onward. Hono's routing followed that rule; its query helpers did not.For one and the same request, this produces an interpretation differential:
The same divergence reaches request validation and any middleware that reads query parameters.
This requires a request target containing a literal
#to reach the application. Deployments on runtimes that normalise such a target — including Cloudflare Workers — are not affected, and neither are those behind an intermediary that strips the fragment.Impact
An attacker can cause the application to act on parameters that components in front of it never observe.
This may lead to:
This issue affects applications that read query parameters and run on a runtime that passes a literal
#through to the request URL.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Hono: Incomplete fix for CVE-2026-39408:
toSSG()still writes files outside the output directoryCVE-2026-84365 / GHSA-gqvv-2mrq-wpjv
More information
Details
Summary
The fix released for CVE-2026-39408 does not cover every traversal sequence.
toSSG()can still write files outside the configured output directory when a route parameter contains consecutive parent-directory segments.Details
Static site generation builds each output path from the route path and the values supplied through
ssgParams, then verifies that the result stays inside the output directory. That check normalizes the path with the same routine that built it, and the routine did not fully collapse runs of consecutive parent-directory segments. A value carrying enough of them produces a path the check accepts, but the filesystem resolves outside the output directory.The earlier fix handled a single parent-directory segment, so it blocks the sequence reported at the time while leaving longer runs unhandled. The check also treated output directories that differ only in how they are rooted as equivalent.
This arises when an application generates a static site from route parameter values it does not fully control — slugs coming from a CMS, an API, or user submissions.
Impact
A value reaching
ssgParamsfrom an untrusted source can cause build output to be written outside the intended output directory, carrying whatever content the route handler produced.This may lead to:
This affects build-time static site generation only; request-time routing is not affected. Applications whose
ssgParamsvalues are entirely developer-controlled are not affected.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
honojs/hono (hono)
v4.13.5Compare Source
Security fixes
This release includes fixes for the following security issues:
Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials
Affects: Cache Middleware and applications behind a proxy, WAF, or logging layer that inspects query strings. Fixes query parsing that did not stop at the URL fragment, so a
?after a#was treated as the start of a query string and the application could read parameters that the other component never saw. GHSA-crvj-82cr-hjcxIncomplete fix for CVE-2026-39408:
toSSG()still writes files outside the output directoryAffects:
toSSG()for Static Site Generation. Fixes a path normalization gap where consecutive parent-directory segments inssgParamsvalues were not fully collapsed, bypassing the containment check added in 4.12.12. GHSA-gqvv-2mrq-wpjvUnbounded dot-notation nesting in
parseBody()can cause memory exhaustionAffects:
parseBody()when dot-notation parsing is enabled. Fixes unbounded expansion of dot-separated field names, where a small request body could allocate a disproportionately large object graph and concurrent requests could exhaust the heap. GHSA-g6gw-c38x-mqfcUsers who use Cache Middleware, deploy behind a proxy or WAF that inspects query strings, use Static Site Generation, or use
parseBody({ dot: true })are strongly encouraged to upgrade to this version.v4.13.4Compare Source
What's Changed
Full Changelog: honojs/hono@v4.13.3...v4.13.4
v4.13.3Compare Source
What's Changed
Full Changelog: honojs/hono@v4.13.2...v4.13.3
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.