v4.12.25

j178/prekv4.12.25Jun 9, 2026by yusukebe

AI Summary

This release focuses on critical security patches for the Hono web framework, addressing vulnerabilities in CORS handling, body limits, and path traversal on Windows.

Key Highlights

  • Fixed CORS Middleware wildcard origin reflecting credentials (GHSA-88fw-hqm2-52qc)
  • Fixed Body Limit Middleware bypass on AWS Lambda via Content-Length (GHSA-rv63-4mwf-qqc2)
  • Fixed Path traversal in serve-static on Windows via encoded backslash (GHSA-wwfh-h76j-fc44)
  • Fixed AWS Lambda adapter merging multiple Set-Cookie headers
  • Fixed Lambda@Edge adapter dropping repeated request headers

New Features

  • Fixed CORS wildcard origin reflecting credentials
  • Fixed AWS Lambda body limit bypass
  • Fixed Windows path traversal vulnerability
  • Fixed Set-Cookie header handling on AWS Lambda
  • Fixed header overwriting on Lambda@Edge

Full Release Notes

## Security fixes

This release includes fixes for the following security issues:

### CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard

Affects: `hono/cors`. Fixes the wildcard origin reflecting the request `Origin` and sending `Access-Control-Allow-Credentials: true` when `credentials: true` is set without an explicit `origin`, where any site a logged-in user visited could make credentialed cross-origin requests and read responses from cookie-authenticated endpoints. GHSA-88fw-hqm2-52qc

### Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`

Affects: `hono/body-limit` on AWS Lambda (`hono/aws-lambda`, `hono/lambda-edge`). Fixes the request being built with the client-declared `Content-Length` while the body is delivered fully buffered, where a client could declare a small `Content-Length` with a much larger body and slip past the configured size limit. GHSA-rv63-4mwf-qqc2

### Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)

Affects: `serveStatic` on Windows (Node, Bun, Deno adapters). Fixes the path guard allowing a lone backslash, where an encoded backslash (`%5C`) decoded to `\` was treated as a separator by the Windows path resolver, letting a single URL segment escape into a middleware-guarded subtree. GHSA-wwfh-h76j-fc44

### AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice

Affects: `hono/aws-lambda`. Fixes multiple `Set-Cookie` response headers being joined into one comma-separated value for ALB single-header responses and VPC Lattice v2, where the value could not be split back into individual cookies and clients silently dropped or misparsed them. GHSA-j6c9-x7qj-28xf

### Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest

Affects: `hono/lambda-edge`. Fixes repeated request headers being written with overwrite instead of append, where only the last value of a header such as `X-Forwarded-For` reached the application and the remaining values were silently dropped. GHSA-wgpf-jwqj-8h8p