claudeenmodel: claude-sonnet-4-20250514
Hono v4.12.4 - Critical Security Fixes
Key Points
- Three critical security vulnerabilities fixed
- SSE and cookie injection attacks prevented
- Serve static middleware bypass resolved
Summary
Hono v4.12.4 addresses three critical security vulnerabilities affecting core components. This is a security-focused release with essential fixes for injection attacks and middleware bypass issues.
Key Security Fixes
- SSE Control Field Injection (GHSA-p6xx-57qc-3wxr): Fixed injection vulnerabilities in
streamSSE()by rejecting CR/LF characters inevent,id, andretryfields - Cookie Attribute Injection (GHSA-5pq2-9x2x-5p6w): Resolved cookie manipulation in
setCookie()by rejecting;,\r, and\ncharacters in domain and path options - Middleware Bypass in Serve Static (GHSA-q5qw-h33p-qvwr): Fixed inconsistent URL decoding that could allow unauthorized access to protected static resources
Other Changes
- Fixed route schema preservation in
ApplyGlobalResponsefor client - Improved return type specification for
tryDecodeURIutility
⚠️ Users utilizing Streaming Helper, Cookie utility, or Serve Static middleware should upgrade immediately.