IP Restriction Bypass in Hono Web Application Framework
CVE-2026-47674

5.3MEDIUM

Key Information:

Vendor

Honojs

Status
Vendor
CVE Published:
28 May 2026

What is CVE-2026-47674?

The Hono Web Application Framework, before version 4.12.21, contains a weakness within its ip-restriction middleware. This flaw allows incoming IP addresses to be improperly validated against configured allow and deny rules due to reliance on string equality following partial normalization. As a result, non-canonical IPv6 address formats, including compressed representations and hex-notation IPv4-mapped addresses, may bypass defined restrictions without alerting users, leaving systems vulnerable to unauthorized access. The issue has been resolved in version 4.12.21.

Affected Version(s)

hono < 4.12.21

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.