IP Restriction Bypass in Hono Web Application Framework
CVE-2026-47674
5.3MEDIUM
What is CVE-2026-47674?
The Hono Web Application Framework, before version 4.12.21, contains a weakness within its ip-restriction middleware. This flaw allows incoming IP addresses to be improperly validated against configured allow and deny rules due to reliance on string equality following partial normalization. As a result, non-canonical IPv6 address formats, including compressed representations and hex-notation IPv4-mapped addresses, may bypass defined restrictions without alerting users, leaving systems vulnerable to unauthorized access. The issue has been resolved in version 4.12.21.
Affected Version(s)
hono < 4.12.21
