Information disclosure in hono - CVE-2026-71849
Published: August 3, 2026 / Updated: August 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper handling of connection-scoped response headers in Proxy Helper (hono/proxy) when forwarding proxied origin responses. A remote attacker can cause an application to proxy a response that names additional headers in the Connection header to disclose sensitive information.
Only applications that proxy responses from origins that list custom header names in the Connection response header are affected.
Affected software
IBM App Connect Enterprise
Informix Dynamic Server
How to mitigate CVE-2026-71849
IBM App Connect Enterprise - update to 13.0.8.2
Informix Dynamic Server - addressed in versions 14.10.FC14W1, 15.0.1.16