v4.12.27

paulpierre/markdown-crawlerv4.12.27Jun 23, 2026by yusukebe

AI Summary

Addresses critical security vulnerabilities in the Hono framework, including context isolation issues in SSR, XSS bypasses in CSS class composition, and header handling logic in AWS Lambda adapters.

Key Highlights

  • Fixed Honon/jsx context isolation per request (GHSA-hvrm-45r6-mjfj)
  • Fixed Server-Side XSS via JSX escaping bypass in cx() (GHSA-w62v-xxxg-mg59)
  • Fixed API Gateway v1 adapter dropping repeated request header values (GHSA-xgm2-5f3f-mvvc)

Full Release Notes

## Security fixes

This release includes fixes for the following security issues:

### hono/jsx does not isolate context per request

Affects: `hono/jsx`, `hono/jsx-renderer`. During SSR, context was stored process-wide instead of per request, so `useContext()`/`useRequestContext()` read after an `await` in an async component could return another concurrent request's value β€” leading to cross-request data disclosure or authorization checks against the wrong request. GHSA-hvrm-45r6-mjfj

### Server-Side XSS via JSX escaping bypass in cx()

Affects: `hono/css`. `cx()` marked its composed class name as already-escaped without escaping the input, so untrusted input passed as a class name could break out of the JSX `class` attribute during SSR and inject markup (XSS). GHSA-w62v-xxxg-mg59

### API Gateway v1 adapter can drop a repeated request header value

Affects: `hono/aws-lambda`. The API Gateway v1 (and VPC Lattice) adapter de-duplicated repeated header values by substring instead of exact match, dropping a value that is a substring of another (e.g. `203.0.113.1` dropped when `203.0.113.10` is present) β€” affecting logic such as `X-Forwarded-For`-based IP restriction. GHSA-xgm2-5f3f-mvvc

---

Users of `hono/jsx`/`hono/jsx-renderer`, `hono/css` (`cx()`), or the `hono/aws-lambda` API Gateway v1 / VPC Lattice adapters are encouraged to upgrade.