Medium severity6.5GHSA Advisory· Published May 13, 2026· Updated May 13, 2026
CVE-2026-44456
CVE-2026-44456
Description
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does not reliably enforce maxSize for requests without a usable Content-Length (e.g. Transfer-Encoding: chunked). Oversized requests can reach handlers and return 200 instead of 413. This vulnerability is fixed in 4.12.16.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
hononpm | < 4.12.16 | 4.12.16 |
Affected products
14- osv-coords12 versionspkg:apk/chainguard/hono-service-authpkg:apk/chainguard/hono-service-device-registry-jdbcpkg:apk/chainguard/kibana-9.1pkg:apk/chainguard/kibana-9.1-iamguardedpkg:apk/chainguard/kibana-9.3pkg:apk/chainguard/kibana-9.3-iamguardedpkg:apk/chainguard/kibana-9.4pkg:apk/chainguard/kibana-9.4-iamguardedpkg:apk/chainguard/librechatpkg:apk/chainguard/wazuh-dashboardpkg:apk/chainguard/wazuh-dashboard-fipspkg:npm/hono
< 0+ 11 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 9.1.10-r15
- (no CPE)range: < 9.1.10-r15
- (no CPE)range: < 9.3.4-r4
- (no CPE)range: < 9.3.4-r4
- (no CPE)range: < 9.4.2-r0
- (no CPE)range: < 9.4.2-r0
- (no CPE)range: < 0.8.4-r6
- (no CPE)range: < 4.14.4-r4
- (no CPE)range: < 4.14.4-r3
- (no CPE)range: < 4.12.16
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-9vqf-7f2p-gf9vghsaADVISORY
- github.com/honojs/hono/security/advisories/GHSA-9vqf-7f2p-gf9vnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-44456ghsaADVISORY
News mentions
0No linked articles in our index yet.