claudeenmodel: claude-sonnet-4-20250514
Hono v4.12.12 - Critical Security Fixes Release
Key Points
- 5 critical security vulnerabilities fixed
- Path traversal and middleware bypass issues resolved
- Cookie handling validation improvements
Summary
Hono v4.12.12 is a security-focused release that addresses 5 critical vulnerabilities across multiple components including static file serving, cookie handling, IP restrictions, and static site generation.
Key Points
- Serve Static Middleware: Fixed path normalization bypass via repeated slashes (
//) that could allow access to protected static files - Static Site Generation: Resolved path traversal vulnerability in
toSSG()that allowed writing files outside output directory - IP Restriction Middleware: Fixed incorrect handling of IPv4-mapped IPv6 addresses (e.g.,
::ffff:127.0.0.1) causing rule bypasses - Cookie Utilities: Added missing validation for cookie names in
setCookie(),serialize(), andserializeSigned() - Cookie Parsing: Fixed non-breaking space prefix bypass in
getCookie()that could allow cookie override attacks
Upgrade Recommendation
Users utilizing Serve Static, Static Site Generation, Cookie utilities, or IP restriction middleware should upgrade immediately.