- Fix hono/jsx and hono/jsx-renderer context isolation during SSR to prevent useContext()/useRequestContext() from reading another concurrent request's context value after an await in an async component
- Fix Server-Side XSS vulnerability in hono/css cx() function by properly escaping untrusted input passed as class names
- Fix hono/aws-lambda API Gateway v1 and VPC Lattice adapter to correctly match repeated header values by exact match instead of substring matching
Security fixes
This release includes fixes for the following security issues:
hono/jsx does not isolate context per request
Affects: hono/jsx, hono/jsx-renderer. During SSR, context was stored process-wide instead of per request, so useContext()/useRequestContext() read after an await in an async component could return another concurrent request's value — leading to cross-request data disclosure or authorization checks against the wrong request. GHSA-hvrm-45r6-mjfj
Server-Side XSS via JSX escaping bypass in cx()
Affects: hono/css. cx() marked its composed class name as already-escaped without escaping the input, so untrusted input passed as a class name could break out of the JSX class attribute during SSR and inject markup (XSS). GHSA-w62v-xxxg-mg59
API Gateway v1 adapter can drop a repeated request header value
Affects: hono/aws-lambda. The API Gateway v1 (and VPC Lattice) adapter de-duplicated repeated header values by substring instead of exact match, dropping a value that is a substring of another (e.g. 203.0.113.1 dropped when 203.0.113.10 is present) — affecting logic such as X-Forwarded-For-based IP restriction. GHSA-xgm2-5f3f-mvvc
Users of hono/jsx/hono/jsx-renderer, hono/css (cx()), or the hono/aws-lambda API Gateway v1 / VPC Lattice adapters are encouraged to upgrade.