Inefficient regular expression complexity in hono - CVE-2026-69207
Published: August 3, 2026 / Updated: August 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient regular expression complexity in the built-in CORS middleware when processing the Access-Control-Request-Headers header during a CORS preflight request. A remote attacker can send a specially crafted OPTIONS request with a long whitespace sequence in the header value to cause a denial of service.
Only applications using cors() with the default or an empty allowHeaders setting reach the affected code path.
Affected software
Informix Dynamic Server
IBM App Connect Enterprise
How to mitigate CVE-2026-69207
Informix Dynamic Server - addressed in versions 14.10.FC14W1, 15.0.1.16
IBM App Connect Enterprise - update to 13.0.8.2