GHSA-79qm-7rj5-m7r9: Infoleak

Published Aug 7, 2026
·
Updated

Summary

The Proxy Helper (hono/proxy) does not remove response headers named by the origin's Connection header. Headers that the origin marked as connection-scoped are therefore forwarded to clients.

Details

Per RFC 9110 Section 7.6.1, an intermediary must remove the header fields listed in a message's Connection header field before forwarding the message, in addition to the well-known hop-by-hop headers. The proxy() function removed the well-known hop-by-hop headers (including Connection itself) from origin responses, but did not remove the headers that the response's Connection header field designated as connection-scoped.

This issue arises when an application proxies responses from an origin that declares additional, non-standard headers as hop-by-hop via the Connection response header.

Impact

A client may receive response headers that the origin intended only for its immediate peer. This may lead to:

- Disclosure of connection-scoped or internal metadata contained in such headers

This issue affects applications that use the Proxy Helper (hono/proxy) to forward responses from origins that list custom header names in their Connection response header. Applications whose origins only use the standard hop-by-hop headers are not affected.

Affected Software

1 affected componentFixes available
npm/hono>=4.7.0<4.12.34
4.12.34

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/hono to a version that resolves this vulnerability.

    Fixed in 4.12.34

Event History

Aug 7, 2026
Advisory Published
via GitHub·06:38 PM
Data Sourced
via GitHub·06:38 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of GHSA-79qm-7rj5-m7r9?

The severity of GHSA-79qm-7rj5-m7r9 is low, rated at 3.7.

2

How do I fix GHSA-79qm-7rj5-m7r9?

To fix GHSA-79qm-7rj5-m7r9, update to the latest version of the hono package where this issue is addressed.

3

What software is affected by GHSA-79qm-7rj5-m7r9?

The vulnerability GHSA-79qm-7rj5-m7r9 affects the npm package hono.

4

What type of vulnerability is GHSA-79qm-7rj5-m7r9?

GHSA-79qm-7rj5-m7r9 is categorized as an information leakage vulnerability.

5

What does GHSA-79qm-7rj5-m7r9 entail?

GHSA-79qm-7rj5-m7r9 entails the proxy not removing certain connection-scoped response headers when forwarding to clients.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203