Executive brief
Hono, a lightweight web framework library, contains a flaw in its URL path parsing logic that could allow attackers to bypass security policies enforced by reverse proxies like Nginx. An attacker could craft a malformed request to access protected endpoints such as /admin that should be blocked, potentially exposing sensitive administrative data. The vulnerability requires specific network conditions and depends on how the application is deployed, but could lead to unauthorized access to confidential information.
Technical details
The vulnerability exists in the getPath utility function, which relies on fixed character offsets when parsing absolute-form Request-URIs. When processing malformed absolute-form request URIs, the fixed offset logic can incorrectly extract the path component, leading to path confusion. An unauthenticated, network-based attacker can send a specially crafted HTTP request to bypass proxy-level access control lists (e.g., Nginx location blocks) without requiring authentication or user interaction. The impact is contingent on the application architecture; many standards-compliant runtimes reject such requests with a 400 status, limiting practical exploitability. The fix correctly locates the first slash after "://" to properly extract the path, and is available in Hono v4.9.6.
Affected products
- Hono Hono >=4.8.0, <4.9.6
Timeline
- 2025-09-03: disclosed
- 2025-09-03: patched: Fixed in Hono v4.9.6