CVE-2026-39409Disclosure(hono / hono)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() does not canonicalize IPv4-mapped IPv6 client addresses (e.g. ::ffff:127.0.0.1) before applying IPv4 allow or deny rules. In environments such as Node.js dual-stack, this can cause IPv4 rules to fail to match, leading to unintended authorization behavior. This vulnerability is fixed in 4.12.12.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-180

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hono

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-08); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
hono

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-08: 2Mentions · 2026-04-09: 1Technical Details · 2026-04-08: 204-0804-09
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-082
Disclosure1General1
2026-04-091
Disclosure1
Full discourse3 posts
  • r74tech@r74tech
    Disclosure

    Hono の脆弱性を2件報告し、CVE が発行されました。 CVE-2026-39409: https://github.com/advisories/GHSA-xpcf-pg52-r92g CVE-2026-39408: https://github.com/advisories/GHSA-xf4j-xp2r-rqqx https://t.co/KGn4XJ2KRi

    Post summary

    Two new vulnerabilities for Hono were disclosed, with CVE IDs and links to GitHub advisories provided.

    17072119.3K
    362 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-39409 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() does not canonicalize IPv4-mapped IPv6 client … https://www.cve.org/CVERecord?id=CVE-2026-39409 ----- Traducción: CVE-2026-39409 Hon… http://infoflow.cloud`

    Post summary

    CVE‑2026‑39409 highlights a flaw in Hono’s ipRestriction() function that fails to canonicalize IPv4‑mapped IPv6 clients before version 4.12.12. No exploit, PoC, patch, or active exploitation information is provided.

    0000035
    67 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-39409 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() does not canonicalize IPv4-mapped IPv6 client … https://www.cve.org/CVERecord?id=CVE-2026-39409

    Post summary

    The text references CVE-2026-39409 in Hono, highlighting a canonicalization issue with IPv4-mapped IPv6 clients before version 4.12.12, but does not provide a PoC, exploit code, patch details, or evidence of active exploitation.

    00000134
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphonohono-node.js-

Explore more