CVE-2026-59897: CWE-348: Use of Less Trusted Source in honojs hono
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a substring comparison instead of an exact match, so middleware or application logic that depends on the complete X-Forwarded-For chain, rate limiting, audit logging, or proxy-chain validation can receive incomplete data. This issue is fixed in version 4.12.27.
AI Analysis
Technical Summary
The Hono web application framework's AWS API Gateway v1 adapter versions >=4.3.3 and <4.12.27 improperly handle repeated request header values by de-duplicating them based on substring comparison rather than exact matches. This leads to loss of distinct repeated header values, affecting components that rely on the complete X-Forwarded-For chain for functionality like rate limiting, audit logging, or proxy-chain validation. The vulnerability is identified as CWE-348 (Use of Less Trusted Source) and is resolved in version 4.12.27.
Potential Impact
Middleware or application logic that depends on the complete X-Forwarded-For header chain may receive incomplete or inaccurate data, potentially impacting rate limiting, audit logging, and proxy-chain validation. This can reduce the reliability of security controls and monitoring that rely on accurate client IP information. The CVSS score is 4.8 (medium severity), indicating limited confidentiality and integrity impact with no availability impact.
Mitigation Recommendations
A patch is available and the issue is fixed in Hono version 4.12.27. Users should upgrade to version 4.12.27 or later to resolve this vulnerability. Since this is a cloud service, the vendor manages remediation for the cloud-hosted service; users should verify with the vendor that the service is updated accordingly.
CVE-2026-59897: CWE-348: Use of Less Trusted Source in honojs hono
Description
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a substring comparison instead of an exact match, so middleware or application logic that depends on the complete X-Forwarded-For chain, rate limiting, audit logging, or proxy-chain validation can receive incomplete data. This issue is fixed in version 4.12.27.
CVSS v3.1
Score 4.8medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Hono web application framework's AWS API Gateway v1 adapter versions >=4.3.3 and <4.12.27 improperly handle repeated request header values by de-duplicating them based on substring comparison rather than exact matches. This leads to loss of distinct repeated header values, affecting components that rely on the complete X-Forwarded-For chain for functionality like rate limiting, audit logging, or proxy-chain validation. The vulnerability is identified as CWE-348 (Use of Less Trusted Source) and is resolved in version 4.12.27.
Potential Impact
Middleware or application logic that depends on the complete X-Forwarded-For header chain may receive incomplete or inaccurate data, potentially impacting rate limiting, audit logging, and proxy-chain validation. This can reduce the reliability of security controls and monitoring that rely on accurate client IP information. The CVSS score is 4.8 (medium severity), indicating limited confidentiality and integrity impact with no availability impact.
Mitigation Recommendations
A patch is available and the issue is fixed in Hono version 4.12.27. Users should upgrade to version 4.12.27 or later to resolve this vulnerability. Since this is a cloud service, the vendor manages remediation for the cloud-hosted service; users should verify with the vendor that the service is updated accordingly.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-07T16:40:07.984Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Is Cloud Service
- true
Threat ID: 6a4e7ad4c9d9e3dbe36a7d7c
Added to database: 07/08/2026, 16:29:08 UTC
Last enriched: 07/16/2026, 10:14:15 UTC
Last updated: 08/22/2026, 10:52:10 UTC
Views: 72
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.