Skip to content

chore(hono): Update dependency hono to v4.13.7 [SECURITY] - #10055

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-hono-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-hono-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
hono (source) 4.13.4 → 4.13.7 age adoption passing confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials

CVE-2026-84363 / GHSA-crvj-82cr-hjcx

More information

Details

Summary

Hono's query parsing does not stop at the URL fragment: a ? appearing after a # is treated as the start of a query string. As a result, the application can read request parameters that no other component involved in handling the request can see.

Details

A fragment is never part of the query, and every standard URL consumer — browsers, new URL(), reverse proxies — ignores everything from the first # onward. Hono's routing followed that rule; its query helpers did not.

For one and the same request, this produces an interpretation differential:

  • A component in front of the application that inspects the query string — filtering rules, parameter allow/deny lists, access logging — observes no parameters, while the application reads and acts on them.
  • The cache middleware removed the fragment when building its cache key, so a response influenced by parameters carried inside the fragment could be stored under a key that did not reflect them and later returned to other users.

The same divergence reaches request validation and any middleware that reads query parameters.

This requires a request target containing a literal # to reach the application. Deployments on runtimes that normalise such a target — including Cloudflare Workers — are not affected, and neither are those behind an intermediary that strips the fragment.

Impact

An attacker can cause the application to act on parameters that components in front of it never observe.

This may lead to:

  • filtering rules, allow/deny lists, and audit logging being blind to parameters the application still processes
  • a cached response being stored under a key that does not reflect the parameters used to produce it, and served to other users
  • stored cross-site scripting, where such a parameter is reflected into a cached HTML response without escaping

This issue affects applications that read query parameters and run on a runtime that passes a literal # through to the request URL.

Severity

  • CVSS Score: 5.9 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Hono: Unbounded dot-notation nesting in parseBody() can cause memory exhaustion

CVE-2026-84364 / GHSA-g6gw-c38x-mqfc

More information

Details

Summary

When parseBody() expands dot-separated form field names into nested objects, it does not limit the nesting depth or the total number of objects created. A request body well within a normal size limit can therefore allocate an object graph far larger than the request itself, and concurrent requests can exhaust the heap and terminate the process.

Details

Each dot-separated segment of a field name creates an intermediate object. Neither the segments within a single field name nor the total across a request was bounded, and empty segments were preserved, so a field name could encode one nesting level per byte.

Both shapes produce the effect: a single deeply dotted field name, and a large number of shallowly dotted ones within one body. A request body size limit does not prevent it, because the amplification happens after the body has been accepted.

Dot-notation parsing is not enabled by default.

Impact

An attacker who can reach an endpoint that parses request bodies with dot-notation enabled can send concurrent requests whose memory cost is disproportionate to their size.

This may lead to:

  • exhaustion of the JavaScript heap and termination of the server process
  • the service remaining unavailable until it is restarted

This issue affects applications that explicitly enable dot-notation parsing. Applications using the default behaviour are not affected.

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Hono: Incomplete fix for CVE-2026-39408: toSSG() still writes files outside the output directory

CVE-2026-84365 / GHSA-gqvv-2mrq-wpjv

More information

Details

Summary

The fix released for CVE-2026-39408 does not cover every traversal sequence. toSSG() can still write files outside the configured output directory when a route parameter contains consecutive parent-directory segments.

Details

Static site generation builds each output path from the route path and the values supplied through ssgParams, then verifies that the result stays inside the output directory. That check normalizes the path with the same routine that built it, and the routine did not fully collapse runs of consecutive parent-directory segments. A value carrying enough of them produces a path the check accepts, but the filesystem resolves outside the output directory.

The earlier fix handled a single parent-directory segment, so it blocks the sequence reported at the time while leaving longer runs unhandled. The check also treated output directories that differ only in how they are rooted as equivalent.

This arises when an application generates a static site from route parameter values it does not fully control — slugs coming from a CMS, an API, or user submissions.

Impact

A value reaching ssgParams from an untrusted source can cause build output to be written outside the intended output directory, carrying whatever content the route handler produced.

This may lead to:

  • files being created or overwritten elsewhere in the build environment
  • generated artifacts or deployment output being altered

This affects build-time static site generation only; request-time routing is not affected. Applications whose ssgParams values are entirely developer-controlled are not affected.

Severity

  • CVSS Score: 6.5 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


hono/jsx renders plain strings unescaped in boundary components, leading to XSS

CVE-2026-93981 / GHSA-hxh3-vqpv-xpqv

More information

Details

Summary

hono/jsx does not HTML-escape a plain string placed directly as a child or fallback of Suspense or ErrorBoundary, as the only child of a Context.Provider, or as the root value of renderToString() / renderToReadableStream() from hono/jsx/dom/server. Such a string is emitted as markup instead of text.

Details

These paths stringify their input and treat the result as already-escaped HTML, so a plain string passes through unchanged. Notable cases:

  • Suspense: a string child, or a string fallback while a child suspends. With streaming, the fallback reaches the browser in the initial chunk.
  • ErrorBoundary: a string child alongside an asynchronous sibling. The all-synchronous case was fixed in 4.11.7 (GHSA-9r54-q6cx-xmh5).
  • Context.Provider: a single string child. Multiple children are escaped.
  • hono/jsx/dom/server: a string, or an array containing strings, passed as the root.

A lone {children} forwarded by a wrapper component is enough to reach these paths. Strings wrapped in an element, values from raw() or the html helper, and client-side rendering with hono/jsx/dom are not affected.

Impact

An attacker who controls a string rendered in an affected position can inject arbitrary HTML into the server-rendered page, leading to cross-site scripting under the application's origin.

This issue affects applications that render untrusted strings directly in one of the positions above during server-side rendering.

Severity

  • CVSS Score: 4.7 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

honojs/hono (hono)

v4.13.7

Compare Source

v4.13.6

Compare Source

v4.13.5

Compare Source


Configuration

📅 Schedule: (in timezone GMT)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Oct 3, 2026
@vercel

vercel Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
clerk-js-sandbox Ready Ready Preview Oct 3, 2026 11:11pm UTC
swingset Ready Ready Preview Oct 3, 2026 11:11pm UTC

Request Review

@renovate
renovate Bot enabled auto-merge (squash) October 3, 2026 23:08
@changeset-bot

changeset-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 5dd0616

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@renovate

renovate Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: pnpm-lock.yaml

<--- Last few GCs --->

[1340:0x74fd000]   181591 ms: Scavenge 1448.7 (1465.1) -> 1444.3 (1465.2) MB, pooled: 0 MB, 6.30 / 0.00 ms  (average mu = 0.303, current mu = 0.274) allocation failure; 
[1340:0x74fd000]   182986 ms: Mark-Compact (reduce) 1450.1 (1467.2) -> 1438.4 (1448.6) MB, pooled: 0 MB, 41.13 / 0.11 ms  (+ 1317.8 ms in 68 steps since start of marking, biggest step 23.8 ms, walltime since start of marking 1394 ms) (average mu = 0.293, 
FATAL ERROR: Ineffective mark-compacts near heap limit Allocation failed - JavaScript heap out of memory
----- Native stack trace -----

 1: 0x73f8c4 node::OOMErrorHandler(char const*, v8::OOMDetails const&) [/opt/containerbase/tools/node/24.15.0/bin/node]
 2: 0xc06f90  [/opt/containerbase/tools/node/24.15.0/bin/node]
 3: 0xc0707f  [/opt/containerbase/tools/node/24.15.0/bin/node]
 4: 0xeaa885  [/opt/containerbase/tools/node/24.15.0/bin/node]
 5: 0xeaa8b2  [/opt/containerbase/tools/node/24.15.0/bin/node]
 6: 0xeaabaa  [/opt/containerbase/tools/node/24.15.0/bin/node]
 7: 0xebb8aa  [/opt/containerbase/tools/node/24.15.0/bin/node]
 8: 0xebfc50  [/opt/containerbase/tools/node/24.15.0/bin/node]
 9: 0x1953f71  [/opt/containerbase/tools/node/24.15.0/bin/node]
/usr/local/bin/node: line 18:  1340 Aborted                 /opt/containerbase/tools/node/24.15.0/bin/node "$@"

@coderabbitai

coderabbitai Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository YAML (base), Organization UI (inherited)
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 842b5ae1-419a-407d-bf2b-97c14c7d1aed

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Oct 3, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@10055

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@10055

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@10055

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@10055

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@10055

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@10055

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@10055

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@10055

@clerk/expo-biometrics

npm i https://pkg.pr.new/@clerk/expo-biometrics@10055

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@10055

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@10055

@clerk/express

npm i https://pkg.pr.new/@clerk/express@10055

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@10055

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@10055

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@10055

@clerk/mosaic

npm i https://pkg.pr.new/@clerk/mosaic@10055

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@10055

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@10055

@clerk/react

npm i https://pkg.pr.new/@clerk/react@10055

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@10055

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@10055

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@10055

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@10055

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@10055

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@10055

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@10055

commit: 5dd0616

This branch was successfully deployed

2 active deployments
Preview – swingset — 5dd0616c Deployed Oct 3, 2026 by vercel[bot]
Preview – clerk-js-sandbox — 5dd0616c Deployed Oct 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants