Improperly Implemented Security Check for Standard Affecting hono package, versions <4.12.25


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.01% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-HONO-17356391
  • published17 Jun 2026
  • disclosed16 Jun 2026
  • creditRootingg

Introduced: 16 Jun 2026

NewCVE-2026-54289  (opens in a new tab)
CWE-358  (opens in a new tab)

How to fix?

Upgrade hono to version 4.12.25 or higher.

Overview

hono is an Ultrafast web framework for the Edges

Affected versions of this package are vulnerable to Improperly Implemented Security Check for Standard in the Lambda@Edge adapter that truncates repeated request headers. An attacker can bypass access restrictions or affect auditing mechanisms by sending repeated request headers, causing only the last value to be processed and earlier values to be ignored.

CVSS Base Scores

version 4.0
version 3.1