Vulnerability Description
@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware protections (e.g. protecting /admin/*), inconsistent URL decoding can allow protected static resources to be accessed without authorization. In particular, paths containing encoded slashes (%2F) may be evaluated differently by routing/middleware matching versus static file path resolution, enabling a bypass where middleware does not run but the static file is still served. This issue has been patched in version 1.19.10.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hono | Node-Server | < 1.19.10 |
Related Weaknesses (CWE)
References
- https://github.com/honojs/node-server/commit/455015be1697dd89974a68b70350ea7b2d1Patch
- https://github.com/honojs/node-server/security/advisories/GHSA-wc8c-qw6v-h7f6Vendor Advisory
FAQ
What is CVE-2026-29087?
CVE-2026-29087 is a vulnerability with a CVSS score of 7.5 (HIGH). @hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware protections (e.g. pr...
How severe is CVE-2026-29087?
CVE-2026-29087 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-29087?
Check the references section above for vendor advisories and patch information. Affected products include: Hono Node-Server.