v4.12.25

supertone-oss-archive/supertonicv4.12.25Jun 9, 2026by yusukebe

AI Summary

Hono v4.12.25 addresses multiple security vulnerabilities including CORS reflection issues, Body Limit bypasses on AWS Lambda, and path traversal on Windows.

Key Highlights

  • Fixes CORS middleware reflecting wildcard origin with credentials
  • Fixes Body Limit middleware bypass on AWS Lambda
  • Fixes path traversal in serve-static on Windows via encoded backslash
  • Fixes AWS Lambda adapter merging multiple Set-Cookie headers

New Features

  • Security patches for CORS, Body Limit, Path Traversal, and Cookie handling

Full Release Notes

## Security fixes

This release includes fixes for the following security issues:

### CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard

Affects: `hono/cors`. Fixes the wildcard origin reflecting the request `Origin` and sending `Access-Control-Allow-Credentials: true` when `credentials: true` is set without an explicit `origin`, where any site a logged-in user visited could make credentialed cross-origin requests and read responses from cookie-authenticated endpoints. GHSA-88fw-hqm2-52qc

### Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`

Affects: `hono/body-limit` on AWS Lambda (`hono/aws-lambda`, `hono/lambda-edge`). Fixes the request being built with the client-declared `Content-Length` while the body is delivered fully buffered, where a client could declare a small `Content-Length` with a much larger body and slip past the configured size limit. GHSA-rv63-4mwf-qqc2

### Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)

Affects: `serveStatic` on Windows (Node, Bun, Deno adapters). Fixes the path guard allowing a lone backslash, where an encoded backslash (`%5C`) decoded to `\` was treated as a separator by the Windows path resolver, letting a single URL segment escape into a middleware-guarded subtree. GHSA-wwfh-h76j-fc44

### AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice

Affects: `hono/aws-lambda`. Fixes multiple `Set-Cookie` response headers being joined into one comma-separated value for ALB single-header responses and VPC Lattice v2, where the value could not be split back into individual cookies and clients silently dropped or misparsed them. GHSA-j6c9-x7qj-28xf

### Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest

Affects: `hono/lambda-edge`. Fixes repeated request headers being written with overwrite instead of append, where only the last value of a header such as `X-Forwarded-For` reached the application and the remaining values were silently dropped. GHSA-wgpf-jwqj-8h8p