v4.13.5

honojs/honov4.13.5Aug 26, 2026by yusukebe

AI Summary

This release addresses critical security vulnerabilities affecting Cache Middleware, Static Site Generation, and request body parsing. It fixes a query parser issue that reads parameters after URL fragments and resolves a memory exhaustion vulnerability in `parseBody()`.

Key Highlights

  • Fixed query parser reading parameters after URL fragments (GHSA-crvj-82cr-hjcx).
  • Fixed `toSSG()` writing files outside the output directory (GHSA-gqvv-2mrq-wpjv).
  • Fixed unbounded dot-notation nesting in `parseBody()` causing memory exhaustion (GHSA-g6gw-c38x-mqfc).

Full Release Notes

## Security fixes

This release includes fixes for the following security issues:

### Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials

Affects: Cache Middleware and applications behind a proxy, WAF, or logging layer that inspects query strings. Fixes query parsing that did not stop at the URL fragment, so a `?` after a `#` was treated as the start of a query string and the application could read parameters that the other component never saw. GHSA-crvj-82cr-hjcx

### Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory

Affects: `toSSG()` for Static Site Generation. Fixes a path normalization gap where consecutive parent-directory segments in `ssgParams` values were not fully collapsed, bypassing the containment check added in 4.12.12. GHSA-gqvv-2mrq-wpjv

### Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion

Affects: `parseBody()` when dot-notation parsing is enabled. Fixes unbounded expansion of dot-separated field names, where a small request body could allocate a disproportionately large object graph and concurrent requests could exhaust the heap. GHSA-g6gw-c38x-mqfc

---

Users who use Cache Middleware, deploy behind a proxy or WAF that inspects query strings, use Static Site Generation, or use `parseBody({ dot: true })` are strongly encouraged to upgrade to this version.