v4.12.27

labring/sealosv4.12.27Jun 23, 2026by yusukebe

AI Summary

This security-focused release fixes critical vulnerabilities in the Hono framework, including cross-request data disclosure in Server-Side Rendering (SSR), potential Server-Side XSS via the `cx()` class function, and header dropping issues in the AWS Lambda adapter.

Key Highlights

  • Security fix for hono/jsx: Context was not isolated per request, leading to cross-request data disclosure
  • Security fix for hono/css: XSS bypass via the `cx()` class function
  • Security fix for hono/aws-lambda: API Gateway v1 adapter dropping repeated header values
  • Affected modules: hono/jsx, hono/css, hono/aws-lambda

New Features

  • SSR context isolation security patch
  • XSS vulnerability patch for CSS class composition
  • HTTP header handling fix for AWS Lambda adapter

Full Release Notes

## Security fixes

This release includes fixes for the following security issues:

### hono/jsx does not isolate context per request

Affects: `hono/jsx`, `hono/jsx-renderer`. During SSR, context was stored process-wide instead of per request, so `useContext()`/`useRequestContext()` read after an `await` in an async component could return another concurrent request's value — leading to cross-request data disclosure or authorization checks against the wrong request. GHSA-hvrm-45r6-mjfj

### Server-Side XSS via JSX escaping bypass in cx()

Affects: `hono/css`. `cx()` marked its composed class name as already-escaped without escaping the input, so untrusted input passed as a class name could break out of the JSX `class` attribute during SSR and inject markup (XSS). GHSA-w62v-xxxg-mg59

### API Gateway v1 adapter can drop a repeated request header value

Affects: `hono/aws-lambda`. The API Gateway v1 (and VPC Lattice) adapter de-duplicated repeated header values by substring instead of exact match, dropping a value that is a substring of another (e.g. `203.0.113.1` dropped when `203.0.113.10` is present) — affecting logic such as `X-Forwarded-For`-based IP restriction. GHSA-xgm2-5f3f-mvvc

---

Users of `hono/jsx`/`hono/jsx-renderer`, `hono/css` (`cx()`), or the `hono/aws-lambda` API Gateway v1 / VPC Lattice adapters are encouraged to upgrade.