Double Decoding of the Same Data in hono - #VU152732
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass middleware protections for static files.
The vulnerability exists due to double decoding of the request path in the serveStatic middleware when handling a malformed percent-encoded request path. A remote attacker can send a crafted request that is routed as one path and resolved as another to bypass middleware protections for static files.
Only applications that mount middleware on a portion of the directory served by serveStatic are affected; files remain resolved within the configured root.