v3.21.0
3 rules from daily threat intel (445 → 448 rules / 38 tools):
- VG1092 — Hono < 4.12.25 CORS origin reflection with credentials (CVE-2026-54290 / GHSA-88fw-hqm2-52qc) + June cluster re-fixes (cache leak, JWT NumericDate, bodyLimit). Residual 4.12.18–4.12.24 window, no double-fire with the pre-4.12.18 cluster.
- VG1093 — @hono/node-server < 1.19.13 serveStatic middleware bypass via repeated slashes (GHSA-92pp-h63x-v22m).
- VG1094 — behavioral CORS origin reflection with credentials (origin:true or reflecting arrow fn + credentials:true).
Dogfood: bumped transitive hono override to ^4.12.25. Zero new runtime dependencies.