Inefficient Algorithmic Complexity in hono - CVE-2026-71848
Published: August 3, 2026 / Updated: August 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to algorithmic complexity in languageDetector middleware when processing crafted language tags with a large number of hyphen-separated subtags. A remote attacker can send a specially crafted request to cause a denial of service.
Language values may be sourced from a query parameter, cookie, Accept-Language header, or URL path depending on configuration, and the default detector order exposes query-string, cookie, and header-based processing.
Affected software
IBM App Connect Enterprise
Informix Dynamic Server
How to mitigate CVE-2026-71848
IBM App Connect Enterprise - update to 13.0.8.2
Informix Dynamic Server - addressed in versions 14.10.FC14W1, 15.0.1.16