v4.12.25

medusajs/medusav4.12.25Jun 9, 2026by yusukebe

AI Summary

This release addresses multiple critical security vulnerabilities affecting CORS middleware, body limits, path traversal on Windows, and AWS Lambda/Edge adapter behaviors.

Key Highlights

  • Fixed CORS middleware reflecting any Origin with credentials when origin defaults to wildcard
  • Fixed Body Limit Middleware bypass on AWS Lambda by understating Content-Length
  • Fixed path traversal in serve-static on Windows via encoded backslash (%5C)
  • Fixed AWS Lambda adapter merging multiple Set-Cookie headers, dropping cookies on ALB
  • Fixed Lambda@Edge adapter keeping only the last value of repeated request headers

Full Release Notes

## Security fixes

This release includes fixes for the following security issues:

### CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard

Affects: `hono/cors`. Fixes the wildcard origin reflecting the request `Origin` and sending `Access-Control-Allow-Credentials: true` when `credentials: true` is set without an explicit `origin`, where any site a logged-in user visited could make credentialed cross-origin requests and read responses from cookie-authenticated endpoints. GHSA-88fw-hqm2-52qc

### Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`

Affects: `hono/body-limit` on AWS Lambda (`hono/aws-lambda`, `hono/lambda-edge`). Fixes the request being built with the client-declared `Content-Length` while the body is delivered fully buffered, where a client could declare a small `Content-Length` with a much larger body and slip past the configured size limit. GHSA-rv63-4mwf-qqc2

### Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)

Affects: `serveStatic` on Windows (Node, Bun, Deno adapters). Fixes the path guard allowing a lone backslash, where an encoded backslash (`%5C`) decoded to `\` was treated as a separator by the Windows path resolver, letting a single URL segment escape into a middleware-guarded subtree. GHSA-wwfh-h76j-fc44

### AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice

Affects: `hono/aws-lambda`. Fixes multiple `Set-Cookie` response headers being joined into one comma-separated value for ALB single-header responses and VPC Lattice v2, where the value could not be split back into individual cookies and clients silently dropped or misparsed them. GHSA-j6c9-x7qj-28xf

### Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest

Affects: `hono/lambda-edge`. Fixes repeated request headers being written with overwrite instead of append, where only the last value of a header such as `X-Forwarded-For` reached the application and the remaining values were silently dropped. GHSA-wgpf-jwqj-8h8p