Input validation error in hono - CVE-2025-58362
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper input validation in the getPath utility function when parsing malformed absolute-form request-uris. A remote attacker can send a specially crafted request to disclose sensitive information.
Exploitation may enable bypass of proxy-level ACLs protecting sensitive endpoints such as /admin, and the impact depends on the application and environment because many standards-compliant runtimes and reverse proxies reject such malformed requests.