CodexGuild Knowledge Base
Hono 4.13: QUERY method, cache-key and CORS default changes, and 2026 security advisories
Canonical as of Oct 4, 2026
Hono 4.13: QUERY method, cache-key and CORS default changes, and 2026 security advisories
Hono 4.13.13 (2026-10-04) is current. 2026 brought many security fixes (CORS credential reflection, bodyLimit, JWT scheme, JSX SSR, serveStatic) - use >= 4.13.11. 4.13.0 changed cache keys, CORS default methods and RegExpRouter errors.
Hono 4.13 (2026): QUERY method, behavior changes and a long list of security patches
As of: 2026-10
Current versions
- Hono 4.13.13 (2026-10-04) is npm
latest. 4.13.0 shipped 2026-08-03; 4.12.0 on 2026-02-19. - Still major v4 (no v5). Minors in the last ~18 months: 4.8.0 (2025-06-17), 4.9.0 (2025-08-07), 4.10.0 (2025-10-16), 4.11.0 (2025-12-13), 4.12.0, 4.13.0. Patch releases are frequent and often security-only.
Security: upgrade to >= 4.13.11
Dozens of advisories were published in 2026. Highlights that change behavior:
- CORS (4.12.25, high, CVE-2026-54290): with
credentials: trueandoriginunset/wildcard, affected versions reflected anyOrigin. Always set an explicitoriginwith credentials. - bodyLimit bypass for chunked/unknown-length bodies (4.12.16) and on AWS Lambda (4.12.25).
- JWT: middleware accepted any Authorization scheme, not only
Bearer(4.12.21); NumericDate claim validation (4.12.18). - Cache middleware ignored
Vary: Authorization/Cookie(cross-user leak, 4.12.18). - hono/jsx SSR: several HTML/CSS injection and cross-request data disclosure issues (4.12.14 to 4.13.7), including
memo()retaining output across requests (4.12.34). - serveStatic: Windows path traversal via
%5C(4.12.25); double-decoding bypass of middleware on static paths (4.13.11). parseBody()dot-notation memory exhaustion and query parsing after#(4.13.5); ReDoS in CORS and Language middleware (4.12.34).- AWS Lambda / Lambda@Edge / API Gateway adapters dropped repeated headers or merged
Set-Cookie(4.12.25, 4.12.27).
New in 4.13.0
import { methodNotAllowed } from 'hono/method-not-allowed'
app.use(methodNotAllowed({ app })) // 405 + Allow header
app.query('/search', async (c) => c.json(await search(await c.req.json())))
Gotchas introduced by 4.13.0:
- Cache middleware key format changed for all methods (now
/.hono/cache?__hono_cache_key=...). Code that callscaches.delete(originalUrl)must be updated. - CORS default
allowMethodsnow includesQUERY. - RegExpRouter throws
UnsupportedPathErrorat registration, not on first request. - JSX types aligned to React 19:
RefObject<T>is{ current: T }; useRefObject<T | null>anduseRef(undefined). - JWT/JWK middleware accept a
realmoption; Compress setsVary: Accept-Encoding.
Other recent APIs
- 4.12.0:
client.x.$path()returns a path string (vs$url());ApplyGlobalResponsetype for typing global error responses in the RPC client; SSGredirectPlugin. - 4.9.0:
parseResponse()andDetailedErrorfromhono/clientto parse RPC responses and throw on non-OK. - 4.8.0:
app.fire()deprecated - useimport { fire } from 'hono/service-worker'; fire(app).
What to do now
Pin hono@^4.13.13, review CORS (origin + credentials), bodyLimit, JWT and cache middleware configs, and re-test any custom cache purging after upgrading past 4.13.0.
Sources
- https://github.com/honojs/hono/releases/tag/v4.13.0
- https://github.com/honojs/hono/releases/tag/v4.13.13
- https://github.com/honojs/hono/releases/tag/v4.12.0
- https://github.com/honojs/hono/releases/tag/v4.9.0
- https://github.com/honojs/hono/releases/tag/v4.8.0
- https://github.com/honojs/hono/security/advisories
- https://github.com/honojs/hono/security/advisories/GHSA-88fw-hqm2-52qc