Junglewise Threat Intelligence

CVE-2026-27700: Hono authentication bypass by IP spoofing in AWS Lambda ALB

CVE-2026-27700 · Severity: low · CVSS 3.1 · Published 2026-02-25

Technologies: hono (npm). Vendors: Hono, npm.

Executive brief

Hono is a web framework used to build serverless APIs and web applications on AWS Lambda. When deployed behind an AWS Application Load Balancer, the framework's IP-based access control (used to restrict who can reach certain endpoints) can be bypassed by an attacker sending a forged IP address. This could allow unauthorized access to resources that should be restricted to specific networks or IPs.

Technical details

The vulnerability is an insufficient verification of data authenticity (CWE-345) in the getConnInfo() function of the AWS Lambda adapter. The function incorrectly extracted the first IP address from the X-Forwarded-For header, but AWS ALB appends the real client IP to the end of this header. An attacker can craft a request with a spoofed X-Forwarded-For header; the ALB forwards it with the real IP appended, but Hono trusts the attacker-controlled first value. This bypasses IP-based authorization middleware such as ipRestriction() or any custom middleware relying on getConnInfo() for IP filtering. The vulnerability affects only deployments using the AWS Lambda adapter behind an ALB; API Gateway and Lambda Function URLs are unaffected. The issue was introduced in version 4.12.0 and patched in version 4.12.2.

Affected products

  • Hono Hono 4.12.0 to 4.12.1

Timeline

  • 2026-02-25: disclosed
  • 2026-02-25: patched: Version 4.12.2 released

References

Related threats