Information disclosure in hono - CVE-2026-71849

 

Information disclosure in hono - CVE-2026-71849

Published: August 3, 2026 / Updated: August 8, 2026


Vulnerability identifier: #VU140823
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-71849
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper handling of connection-scoped response headers in Proxy Helper (hono/proxy) when forwarding proxied origin responses. A remote attacker can cause an application to proxy a response that names additional headers in the Connection header to disclose sensitive information.

Only applications that proxy responses from origins that list custom header names in the Connection response header are affected.


Affected software

hono
IBM App Connect Enterprise
Informix Dynamic Server

How to mitigate CVE-2026-71849

Install security update from vendor's website.

hono - update to 4.12.34
IBM App Connect Enterprise - update to 13.0.8.2
Informix Dynamic Server - addressed in versions 14.10.FC14W1, 15.0.1.16

External References

Related Security Bulletins