Junglewise Threat Intelligence

CVE-2026-39409: Hono authorization bypass in ipRestriction middleware

CVE-2026-39409 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Technologies: Honojs Hono. Vendors: npm.

Executive brief

Hono is a web application framework used to build JavaScript-based web services. A vulnerability in its IP restriction component allows attackers to bypass security rules that permit or deny access based on IP addresses. This occurs because the system fails to correctly recognize certain types of network addresses (IPv4-mapped IPv6), potentially allowing unauthorized users to access restricted data or services.

Technical details

The ipRestriction() middleware in Hono classifies client addresses based on their textual representation. Addresses containing a colon (:) are treated as IPv6, including IPv4-mapped IPv6 addresses (e.g., ::ffff:127.0.0.1). Because these are not normalized to IPv4 before rule matching, IPv4 static rules and CIDR ranges fail to match the raw string. In Node.js dual-stack environments, this allows an attacker to bypass 'deny' rules or causes legitimate users to be blocked by 'allow' rules. The issue is fixed in version 4.12.12 by implementing proper address canonicalization.

Affected products

  • honojs Hono < 4.12.12

Timeline

  • 2026-04-07: patched: Fixed in version 4.12.12
  • 2026-04-08: advisory: GitHub Advisory GHSA-xpcf-pg52-r92g published
  • 2026-04-08: disclosed: CVE-2026-39409 published

References

Related threats