chore(hono): Update dependency hono to v4.13.7 [SECURITY] - #10055
renovate[bot] wants to merge 1 commit into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
@clerk/astro
@clerk/backend
@clerk/chrome-extension
@clerk/clerk-js
@clerk/electron
@clerk/electron-passkeys
@clerk/eslint-plugin
@clerk/expo
@clerk/expo-biometrics
@clerk/expo-google-signin
@clerk/expo-passkeys
@clerk/express
@clerk/fastify
@clerk/hono
@clerk/localizations
@clerk/mosaic
@clerk/nextjs
@clerk/nuxt
@clerk/react
@clerk/react-router
@clerk/shared
@clerk/tanstack-react-start
@clerk/testing
@clerk/ui
@clerk/upgrade
@clerk/vue
commit: |
This PR contains the following updates:
4.13.4→4.13.7Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials
CVE-2026-84363 / GHSA-crvj-82cr-hjcx
More information
Details
Summary
Hono's query parsing does not stop at the URL fragment: a
?appearing after a#is treated as the start of a query string. As a result, the application can read request parameters that no other component involved in handling the request can see.Details
A fragment is never part of the query, and every standard URL consumer — browsers,
new URL(), reverse proxies — ignores everything from the first#onward. Hono's routing followed that rule; its query helpers did not.For one and the same request, this produces an interpretation differential:
The same divergence reaches request validation and any middleware that reads query parameters.
This requires a request target containing a literal
#to reach the application. Deployments on runtimes that normalise such a target — including Cloudflare Workers — are not affected, and neither are those behind an intermediary that strips the fragment.Impact
An attacker can cause the application to act on parameters that components in front of it never observe.
This may lead to:
This issue affects applications that read query parameters and run on a runtime that passes a literal
#through to the request URL.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Hono: Unbounded dot-notation nesting in
parseBody()can cause memory exhaustionCVE-2026-84364 / GHSA-g6gw-c38x-mqfc
More information
Details
Summary
When
parseBody()expands dot-separated form field names into nested objects, it does not limit the nesting depth or the total number of objects created. A request body well within a normal size limit can therefore allocate an object graph far larger than the request itself, and concurrent requests can exhaust the heap and terminate the process.Details
Each dot-separated segment of a field name creates an intermediate object. Neither the segments within a single field name nor the total across a request was bounded, and empty segments were preserved, so a field name could encode one nesting level per byte.
Both shapes produce the effect: a single deeply dotted field name, and a large number of shallowly dotted ones within one body. A request body size limit does not prevent it, because the amplification happens after the body has been accepted.
Dot-notation parsing is not enabled by default.
Impact
An attacker who can reach an endpoint that parses request bodies with dot-notation enabled can send concurrent requests whose memory cost is disproportionate to their size.
This may lead to:
This issue affects applications that explicitly enable dot-notation parsing. Applications using the default behaviour are not affected.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Hono: Incomplete fix for CVE-2026-39408:
toSSG()still writes files outside the output directoryCVE-2026-84365 / GHSA-gqvv-2mrq-wpjv
More information
Details
Summary
The fix released for CVE-2026-39408 does not cover every traversal sequence.
toSSG()can still write files outside the configured output directory when a route parameter contains consecutive parent-directory segments.Details
Static site generation builds each output path from the route path and the values supplied through
ssgParams, then verifies that the result stays inside the output directory. That check normalizes the path with the same routine that built it, and the routine did not fully collapse runs of consecutive parent-directory segments. A value carrying enough of them produces a path the check accepts, but the filesystem resolves outside the output directory.The earlier fix handled a single parent-directory segment, so it blocks the sequence reported at the time while leaving longer runs unhandled. The check also treated output directories that differ only in how they are rooted as equivalent.
This arises when an application generates a static site from route parameter values it does not fully control — slugs coming from a CMS, an API, or user submissions.
Impact
A value reaching
ssgParamsfrom an untrusted source can cause build output to be written outside the intended output directory, carrying whatever content the route handler produced.This may lead to:
This affects build-time static site generation only; request-time routing is not affected. Applications whose
ssgParamsvalues are entirely developer-controlled are not affected.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
hono/jsx renders plain strings unescaped in boundary components, leading to XSS
CVE-2026-93981 / GHSA-hxh3-vqpv-xpqv
More information
Details
Summary
hono/jsxdoes not HTML-escape a plain string placed directly as a child orfallbackofSuspenseorErrorBoundary, as the only child of aContext.Provider, or as the root value ofrenderToString()/renderToReadableStream()fromhono/jsx/dom/server. Such a string is emitted as markup instead of text.Details
These paths stringify their input and treat the result as already-escaped HTML, so a plain string passes through unchanged. Notable cases:
Suspense: a string child, or a stringfallbackwhile a child suspends. With streaming, the fallback reaches the browser in the initial chunk.ErrorBoundary: a string child alongside an asynchronous sibling. The all-synchronous case was fixed in 4.11.7 (GHSA-9r54-q6cx-xmh5).Context.Provider: a single string child. Multiple children are escaped.hono/jsx/dom/server: a string, or an array containing strings, passed as the root.A lone
{children}forwarded by a wrapper component is enough to reach these paths. Strings wrapped in an element, values fromraw()or thehtmlhelper, and client-side rendering withhono/jsx/domare not affected.Impact
An attacker who controls a string rendered in an affected position can inject arbitrary HTML into the server-rendered page, leading to cross-site scripting under the application's origin.
This issue affects applications that render untrusted strings directly in one of the positions above during server-side rendering.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
honojs/hono (hono)
v4.13.7Compare Source
v4.13.6Compare Source
v4.13.5Compare Source
Configuration
📅 Schedule: (in timezone GMT)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.