CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-71849

CVE-2026-71849: Information Exposure via Hop-by-Hop Header Leakage in Hono Proxy Helper

Amit Schendel
Amit Schendel
Senior Security Researcher

Aug 7, 2026·6 min read·56 visits

Executive Summary (TL;DR)

Hono's proxy helper failed to dynamically strip custom connection-scoped headers specified in the response's Connection header, leading to information leakage of internal transit headers to clients.

A vulnerability in the Hono framework's Proxy Helper allows the exposure of connection-scoped, internal, or session-specific metadata to unauthorized actors. The proxy helper fails to remove header fields dynamically listed in the response's Connection header, violating RFC 9110 Section 7.6.1.

Vulnerability Overview

Hono is a web framework built on Web Standards with support for multiple JavaScript runtimes including Node.js, Deno, Bun, and Cloudflare Workers. Within this ecosystem, the Proxy Helper (hono/proxy) offers a proxy() utility designed to facilitate forwarding incoming HTTP requests to downstream origin servers. This component is commonly deployed in gateway layers, reverse proxies, and microservices architectures to simplify routing.

Between versions 4.7.0 and 4.12.33, the proxy() function in the Proxy Helper failed to handle connection-scoped headers in accordance with RFC 9110 Section 7.6.1. Specifically, the helper failed to inspect the incoming Connection header of origin responses dynamically, only removing a predefined static set of well-known hop-by-hop headers.

This architectural oversight results in the exposure of sensitive session-specific or internal metadata to unauthorized public clients. When an upstream server marks custom tracking headers or internal tokens as connection-scoped, the vulnerable proxy forwards these values instead of purging them, leading to a direct information leakage.

Root Cause Analysis

The root cause of this vulnerability lies in a protocol implementation defect related to HTTP/1.1 and modern proxy specifications. RFC 9110 Section 7.6.1 distinguishes between end-to-end headers, which must be delivered to the final recipient, and connection-scoped (hop-by-hop) headers, which apply only to a single transport link. Intermediaries must remove all hop-by-hop headers before forwarding an HTTP message.

Standard hop-by-hop headers such as Connection, Keep-Alive, and Transfer-Encoding are universally recognized and typically stripped by default. However, RFC 9110 also permits sender-defined custom hop-by-hop headers. These are dynamically listed as comma-separated values inside the Connection header field itself, signaling to the immediate receiver that they must not be forwarded.

The vulnerable implementation of hono/proxy relied exclusively on a static array named hopByHopHeaders. Because it only iterated over this hardcoded list, the proxy completely ignored the list of dynamic headers contained within the Connection response header value. Any custom header specified inside Connection: X-Custom-Header remained intact in the response headers and was subsequently forwarded to the public client.

Code Path and Patch Analysis

In vulnerable versions of Hono, the proxy function within src/helper/proxy/index.ts fetched the response from the upstream origin and initialized a new Headers object. It then executed a static loop to remove the predefined headers, leaving all other custom fields untouched regardless of the Connection header configuration.

// Vulnerable logic path in Hono
const res = await (customFetch || fetch)(req)
const resHeaders = new Headers(res.headers)
 
// Only stripped the static, well-known hop-by-hop headers
hopByHopHeaders.forEach((header) => {
  resHeaders.delete(header)
})

The patch introduced in commit 720b566290793d4358bf39843adcb7cf4da4548f remediates the issue by dynamically parsing the Connection header before executing the static deletion block. The corrected logic retrieves the Connection value, tokenizes it by commas, trims whitespace, and applies a regex filter to prevent invalid headers from manipulating the execution flow before programmatically deleting them.

// Patched implementation in v4.12.34
const res = await (customFetch || fetch)(req)
const resHeaders = new Headers(res.headers)
 
// Remove headers listed in the response's own Connection header (RFC 9110 Section 7.6.1)
const connectionValue = resHeaders.get('connection')
if (connectionValue) {
  connectionValue
    .split(',')
    .map((h) => h.trim())
    .filter((h) => ALLOWED_TOKEN_PATTERN.test(h))
    .forEach((h) => resHeaders.delete(h))
}
 
hopByHopHeaders.forEach((header) => {
  resHeaders.delete(header)
})

Exploitation Methodology

Exploitation of CVE-2026-71849 does not require an active exploit payload or memory manipulation. Instead, it relies on passive observation of headers returned through the Hono proxy interface. The attack surface exists when the backend server utilizes custom connection-scoped headers to pass localized infrastructure details, routing identifiers, or authentication tokens.

The following flowchart illustrates the communication path and the exact point where data leakage occurs:

As shown in the flow, when the origin backend server includes a dynamic header in the Connection directive, Hono deletes the Connection header itself but leaves the referenced custom header active. An attacker querying the proxy endpoint simply inspects the response headers to gather sensitive structural details or credentials that were meant to remain within the internal network segment.

Critical Bypass and Regression Analysis

During regression analysis, researchers must evaluate the behavior of the ALLOWED_TOKEN_PATTERN validation regex. Under HTTP RFC 9110, valid header name characters include alphanumeric characters as well as specific symbols. If the regex is overly restrictive, certain custom headers used by backends (such as those containing underscores or specialized characters) might be skipped by the filter and erroneously forwarded to the client.

Another area of concern is proxy asymmetry. A robust gateway proxy should sanitize both incoming request headers from clients and outgoing response headers from backends. If the client-to-backend request path does not properly sanitize client-supplied hop-by-hop headers, it may create conditions conducive to HTTP request smuggling or cache poisoning against upstream servers.

Finally, handling duplicate headers across multiple lines represents a potential edge case. Different JavaScript runtime engines (Node.js, Bun, Deno) parse multiple instances of the Connection header differently, sometimes merging them and other times only retaining the last declared value. This parsing variance can lead to incomplete header stripping if the engine fails to extract all tokens.

Remediation and Defensive Strategies

The primary and most effective remediation strategy is to upgrade the hono package to version 4.12.34 or higher. This ensures that the dynamic header sanitization logic is natively enforced inside the proxy helper. Organizations should verify that their dependency files are updated and run fresh installations across all staging and production builds.

If upgrading immediately is not viable, developers should implement a manual wrapper around the proxy() helper function. This wrapper must intercept the returned response, parse the Connection header, and explicitly delete all listed headers from the response header collection before returning the object to the routing cycle.

// Example of a manual mitigation wrapper in Hono middleware
app.get('/proxy-route/*', async (c) => {
  const response = await proxy(`https://backend-origin/${c.req.path}`)
  const safeHeaders = new Headers(response.headers)
  
  const connectionHeader = safeHeaders.get('connection')
  if (connectionHeader) {
    connectionHeader.split(',').forEach((h) => {
      safeHeaders.delete(h.trim())
    })
  }
 
  return new Response(response.body, {
    status: response.status,
    headers: safeHeaders
  })
})

Official Patches

honojsFix commit implementing dynamic connection-scoped header stripping

Fix Analysis (1)

Technical Appendix

CVSS Score
3.7/ 10
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Systems

hono

Affected Versions Detail

Product
Affected Versions
Fixed Version
hono
honojs
>= 4.7.0, < 4.12.344.12.34
AttributeDetail
CWE IDCWE-200
Attack VectorNetwork
CVSS v3.13.7 (Low)
EPSS ScoreNot Available
ImpactInformation Exposure
Exploit StatusNone / Theoretical
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1005Data from Local System
Collection
T1552Unsecured Credentials
Credential Access
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Vulnerability Timeline

Security patch committed
2026-08-03
Release v4.12.34 published
2026-08-03
Vulnerability published on CVE.org
2026-08-07
NVD index date
2026-08-07

References & Sources

  • [1]GitHub Security Advisory GHSA-79qm-7rj5-m7r9
  • [2]Fix Commit
  • [3]Hono Release v4.12.34
  • [4]CVE Record on CVE.org

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•17 minutes ago•CVE-2026-105749
6.5

CVE-2026-105749: Unbounded Table Attributes in Docling Backends Leads to Resource Exhaustion

An uncontrolled resource consumption vulnerability exists in the Docling document conversion library. Maliciously structured HTML, JATS, ODS, or BoxNote inputs containing table cells with excessively large 'rowspan' or 'colspan' attribute values trigger algorithmic complexity conditions. This allows unauthenticated remote attackers to initiate resource exhaustion states, crashing or hanging the target document processing pipeline while bypassing configured timeouts.

Amit Schendel
Amit Schendel
0 views•6 min read
•about 1 hour ago•CVE-2026-105748
4.3

CVE-2026-105748: Local File Inclusion and Arbitrary File Disclosure in Docling Document Parser

A Local File Inclusion (LFI) and Arbitrary File Disclosure vulnerability exists in Docling and Docling Slim versions >= 2.16.0 up to 2.131.0. When parsing serialized DoclingDocument structures using the JSON input format, the backend fails to restrict image URI schemes, allowing remote attackers to retrieve local files and verify path existence on the host system during embedded document export.

Amit Schendel
Amit Schendel
3 views•5 min read
•about 2 hours ago•CVE-2026-105744
7.5

CVE-2026-105744: Arbitrary File Read and Remote Code Execution in Docling Tectonic Engine

Docling, a tool for parsing and processing diverse document formats, is vulnerable to arbitrary file read, arbitrary file write, and potential remote code execution (RCE) in versions 2.94.0 through 2.131.0. The vulnerability occurs when applications configure Docling to use the Tectonic engine for rendering TikZ diagrams into images. Because the compilation did not restrict hazardous TeX primitives or sandbox the environment, an attacker can supply crafted documents containing malicious TikZ definitions to access or modify local files and execute arbitrary commands under the privileges of the processing application.

Amit Schendel
Amit Schendel
4 views•7 min read
•about 3 hours ago•CVE-2026-105743
4.0

CVE-2026-105743: Server-Side Request Forgery Guard Bypass in Docling Document Conversion Engine

An SSRF guard bypass vulnerability in the Docling document conversion engine allows unauthenticated attackers to bypass internal IP access controls. The vulnerability exists due to a DNS rebinding Time-of-Check Time-of-Use (TOCTOU) condition, URL authority parsing inconsistencies, and unvalidated network requests triggered during headless browser page rendering.

Amit Schendel
Amit Schendel
4 views•6 min read
•about 4 hours ago•CVE-2026-105742
3.7

CVE-2026-105742: Sensitive Custom Header Leakage in Docling Image Resource Loader

A technical analysis of CVE-2026-105742 (GHSA-p3fw-7699-7926), a sensitive information disclosure vulnerability in the Docling document processing library. Vulnerable versions of Docling indiscriminately forward custom HTTP headers, such as authentication tokens, to arbitrary third-party origins and during cross-origin redirects while fetching remote image assets from untrusted HTML and EPUB documents.

Alon Barad
Alon Barad
5 views•6 min read
•about 5 hours ago•CVE-2026-106121
4.9

CVE-2026-106121: Denial of Service via Infinite Loop in RabbitMQ Java Client JSON Parser

CVE-2026-106121 is a Denial of Service (DoS) vulnerability in the RabbitMQ Java Client library (amqp-client) affecting versions prior to 5.37.0. The vulnerability resides in the legacy, custom JSON-RPC parsing class com.rabbitmq.tools.json.JSONReader. When parsing malformed or truncated payloads ending within a quoted string or single-line comment, the parser's scanner enters an infinite loop. This occurs because the loop lacks an exit condition for the end-of-input sentinel character returned by the iterator, leading to either CPU exhaustion or a JVM crash from an OutOfMemoryError.

Amit Schendel
Amit Schendel
7 views•6 min read