v4.12.25

OpenSignLabs/OpenSignv4.12.25Jun 9, 2026by yusukebe

AI Summary

This release focuses on critical security patches addressing CORS wildcard origin reflection, body limit bypasses on AWS Lambda, path traversal on Windows, and header handling issues on Lambda platforms.

Key Highlights

  • Fixed CORS middleware reflecting any Origin with credentials when origin defaults to wildcard
  • Fixed body limit middleware bypass on AWS Lambda by understating Content-Length
  • Fixed path traversal in serve-static on Windows via encoded backslash (%5C)
  • Fixed AWS Lambda adapter merging multiple Set-Cookie headers
  • Fixed Lambda@Edge adapter keeping only the last value of repeated request headers

Full Release Notes

## Security fixes

This release includes fixes for the following security issues:

### CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard

Affects: `hono/cors`. Fixes the wildcard origin reflecting the request `Origin` and sending `Access-Control-Allow-Credentials: true` when `credentials: true` is set without an explicit `origin`, where any site a logged-in user visited could make credentialed cross-origin requests and read responses from cookie-authenticated endpoints. GHSA-88fw-hqm2-52qc

### Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`

Affects: `hono/body-limit` on AWS Lambda (`hono/aws-lambda`, `hono/lambda-edge`). Fixes the request being built with the client-declared `Content-Length` while the body is delivered fully buffered, where a client could declare a small `Content-Length` with a much larger body and slip past the configured size limit. GHSA-rv63-4mwf-qqc2

### Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)

Affects: `serveStatic` on Windows (Node, Bun, Deno adapters). Fixes the path guard allowing a lone backslash, where an encoded backslash (`%5C`) decoded to `\` was treated as a separator by the Windows path resolver, letting a single URL segment escape into a middleware-guarded subtree. GHSA-wwfh-h76j-fc44

### AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice

Affects: `hono/aws-lambda`. Fixes multiple `Set-Cookie` response headers being joined into one comma-separated value for ALB single-header responses and VPC Lattice v2, where the value could not be split back into individual cookies and clients silently dropped or misparsed them. GHSA-j6c9-x7qj-28xf

### Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest

Affects: `hono/lambda-edge`. Fixes repeated request headers being written with overwrite instead of append, where only the last value of a header such as `X-Forwarded-For` reached the application and the remaining values were silently dropped. GHSA-wgpf-jwqj-8h8p