Skip to content

v3.21.0

Choose a tag to compare

@goklab goklab released this 18 Jun 07:26

3 rules from daily threat intel (445 → 448 rules / 38 tools):

  • VG1092 — Hono < 4.12.25 CORS origin reflection with credentials (CVE-2026-54290 / GHSA-88fw-hqm2-52qc) + June cluster re-fixes (cache leak, JWT NumericDate, bodyLimit). Residual 4.12.18–4.12.24 window, no double-fire with the pre-4.12.18 cluster.
  • VG1093 — @hono/node-server < 1.19.13 serveStatic middleware bypass via repeated slashes (GHSA-92pp-h63x-v22m).
  • VG1094 — behavioral CORS origin reflection with credentials (origin:true or reflecting arrow fn + credentials:true).

Dogfood: bumped transitive hono override to ^4.12.25. Zero new runtime dependencies.