Executive brief
Hono is a web framework widely used to build serverless applications on Cloudflare Workers. The Serve static Middleware component, used to efficiently deliver static assets, improperly validates file paths in user requests, allowing attackers to access internal asset keys beyond the intended scope. This information disclosure could expose sensitive application data stored in the Workers environment, though attackers cannot modify data or execute code.
Technical details
The vulnerability is a path traversal / directory traversal issue in the Serve static Middleware used with the Cloudflare Workers adapter. Insufficient validation of user-supplied request paths allows attackers to craft requests that resolve to arbitrary keys in Workers asset storage. The attack requires network access to a Hono application running on Cloudflare Workers that uses Serve static Middleware with untrusted request paths; no authentication or user interaction is required. An attacker can achieve information disclosure by reading arbitrary asset keys and internal data, though the vulnerability is limited to read access (no data modification or code execution). The fix is available in Hono version 4.11.7 and later.
Affected products
- Hono Hono < 4.11.7
Timeline
- 2026-01-27: disclosed: Advisory GHSA-w332-q679-j88p published
- 2026-01-27: patched: Fix released in Hono 4.11.7