Information disclosure in hono - #VU140823

 

Information disclosure in hono - #VU140823

Published: August 3, 2026


Vulnerability identifier: #VU140823
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper handling of connection-scoped response headers in Proxy Helper (hono/proxy) when forwarding proxied origin responses. A remote attacker can cause an application to proxy a response that names additional headers in the Connection header to disclose sensitive information.

Only applications that proxy responses from origins that list custom header names in the Connection response header are affected.


Affected software

hono

Remediation

Install security update from vendor's website.

hono - update to 4.12.34

External References