CVE-2026-29085Disclosure(hono / hono)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch hono hono systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using streamSSE() in Streaming Helper, the event, id, and retry fields were not validated for carriage return (\r) or newline (\n) characters. Because the SSE protocol uses line breaks as field delimiters, this could allow injection of additional SSE fields within the same event frame if untrusted input was passed into these fields. This issue has been patched in version 4.12.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hono

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-03-04); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
hono

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-04: 2Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-13: 1Patch / Workaround · 2026-03-04: 1Patch / Workaround · 2026-03-13: 1Technical Details · 2026-03-05: 103-0403-0503-0603-13
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-042
Disclosure2
2026-03-051
Disclosure1
2026-03-061
General1
2026-03-131
Patch1
Full discourse5 posts
  • Saad Fellahi@SaadFellahii
    Patch

    Finally my first CVEs. Hono.js (v4.12.4) • CVE-2026-29086 • CVE-2026-29085 Fastify (v5.8.1) • CVE-2026-3419 Shoutout to @honojs & @fastifyjs for the quick fixes. Write-ups on the exploit chains coming soon. #AppSec #NodeJS #CVE #BugBounty https://t.co/wLne1JffJS

    Post summary

    The tweet announces the CVEs, acknowledges that vendors have released quick fixes, and hints that detailed exploit write‑ups will follow, primarily focusing on remediation rather than active exploitation.

    1002165
    42 followersView on X
  • DailyCVE@dailycve
    General

    🟠 Hono, Injection, #CVE-2026-29085 (Medium) https://dailycve.com/hono-injection-cve-2026-29085-medium/

    Post summary

    The text simply announces the CVE and shares a link to an article without providing further technical or operational details.

    0000031
    166 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-29085 Server-Side Event Injection Vulnerability in Hono Web Framework Before 4.12.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29085

    Post summary

    CVE‑2026‑29085, a Server‑Side Event Injection vulnerability, is disclosed for Hono Web Framework versions prior to 4.12.4; no exploit, patch, or active use information is provided.

    0000037
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-29085 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using streamSSE() in Streaming Helper, the event, … https://www.cve.org/CVERecord?id=CVE-2026-29085 ----- Traducción: CVE-2026-29085 Hon… http://infoflow.cloud`

    Post summary

    The post merely references CVE-2026-29085 and links to its CVE record, providing no detailed technical information or exploit details.

    0000053
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29085 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using streamSSE() in Streaming Helper, the event, … https://www.cve.org/CVERecord?id=CVE-2026-29085

    Post summary

    CVE-2026‑29085 is a vulnerability in the Hono web framework affecting streamSSE() in Streaming Helper, fixed in version 4.12.4.

    00000353
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphonohono-node.js-

Explore more