CVE-2026-29087: @hono/node-server: Authorization bypass for protected static paths via encoded slashes in Serve Static Middleware
@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware protections (e.g. protecting /admin/), inconsistent URL decoding can allow protected static resources to be accessed without authorization. In particular, paths containing encoded slashes (%2F) may be evaluated differently by routing/middleware matching versus static file path resolution, enabling a bypass where middleware does not run but the static file is still served. This issue has been patched in version 1.19.10.
Other sources
Summary
When using @hono/node-server's static file serving together with route-based middleware protections (e.g. protecting /admin/), inconsistent URL decoding can allow protected static resources to be accessed without authorization.
In particular, paths containing encoded slashes (%2F) may be evaluated differently by routing/middleware matching versus static file path resolution, enabling a bypass where middleware does not run but the static file is still served.
Details
The routing layer and the node-server static handler normalize request paths differently. The router preserves %2F as a literal string when matching routes, while the static handler decodes %2F into / before resolving the filesystem path.
Example request:
- /admin%2Fsecret.html
This may: - fail to match middleware intended for /admin/, but - still be resolved by the static handler as /admin/secret.html under the configured static root.
This does not allow access outside the configured static root and is not a path traversal vulnerability.
Impact
An unauthenticated attacker could bypass route-based authorization protections for protected static resources by supplying paths containing encoded slashes.
Applications relying solely on route-based middleware to protect static subpaths under the same static root may have exposed those resources.
— GitHub
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29087?
CVE-2026-29087 has a high severity level due to its potential to allow unauthorized access to protected static resources.
How do I fix CVE-2026-29087?
To fix CVE-2026-29087, upgrade @hono/node-server to version 1.19.10 or later.
What causes the vulnerability CVE-2026-29087?
CVE-2026-29087 is caused by inconsistent URL decoding when serving static files alongside route-based middleware protections.
What software is affected by CVE-2026-29087?
CVE-2026-29087 affects versions of @hono/node-server prior to 1.19.10.
How can I verify if I am vulnerable to CVE-2026-29087?
You can verify your vulnerability to CVE-2026-29087 by checking if your version of @hono/node-server is older than 1.19.10.