Improper Neutralization of Special Elements in Output Used by a Downstream Component in hono - CVE-2026-29085

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in hono - CVE-2026-29085

Published: July 24, 2026


Vulnerability identifier: #VU139313
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-29085
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject unintended SSE fields and disclose sensitive information.

The vulnerability exists due to improper neutralization of special elements in output used by a downstream component in the writeSSE() function of the Streaming Helper when processing user-controlled values in the event, id, or retry fields. A remote attacker can supply input containing carriage return and newline characters to inject unintended SSE fields and disclose sensitive information.

Applications that render event data in an unsafe manner could potentially expose themselves to client-side script injection.


Affected software

hono

How to mitigate CVE-2026-29085

Install security update from vendor's website.

hono - update to 4.12.4

External References

Related Security Bulletins