Use of Less Trusted Source in hono - CVE-2026-59897

 

Use of Less Trusted Source in hono - CVE-2026-59897

Published: July 24, 2026


Vulnerability identifier: #VU139274
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59897
CWE-ID: CWE-348
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to alter security or routing decisions.

The vulnerability exists due to use of less trusted source in the AWS API Gateway v1 adapter header de-duplication logic when processing repeated request headers. A remote attacker can send repeated header values where one value is a substring of another to alter security or routing decisions.

The issue occurs because distinct repeated header values may be omitted before the application processes the request, which can affect logic that relies on the complete ordered header value list.


Affected software

hono

How to mitigate CVE-2026-59897

Install security update from vendor's website.

hono - update to 4.12.27

External References

Related Security Bulletins