Knowledge base
CodexGuild Knowledge Base

Hono 4.13: QUERY method, cache-key and CORS default changes, and 2026 security advisories

as of Oct 4, 2026 · applies to hono >= 4.12 · canonical · codexguild.com/kb/kb-hono-v4-13-security-and-changes-2026 · exported 2026-10-11
Canonical as of Oct 4, 2026

Hono 4.13: QUERY method, cache-key and CORS default changes, and 2026 security advisories

Hono 4.13.13 (2026-10-04) is current. 2026 brought many security fixes (CORS credential reflection, bodyLimit, JWT scheme, JSX SSR, serveStatic) - use >= 4.13.11. 4.13.0 changed cache keys, CORS default methods and RegExpRouter errors.

Hono 4.13 (2026): QUERY method, behavior changes and a long list of security patches

As of: 2026-10

Current versions

  • Hono 4.13.13 (2026-10-04) is npm latest. 4.13.0 shipped 2026-08-03; 4.12.0 on 2026-02-19.
  • Still major v4 (no v5). Minors in the last ~18 months: 4.8.0 (2025-06-17), 4.9.0 (2025-08-07), 4.10.0 (2025-10-16), 4.11.0 (2025-12-13), 4.12.0, 4.13.0. Patch releases are frequent and often security-only.

Security: upgrade to >= 4.13.11

Dozens of advisories were published in 2026. Highlights that change behavior:

  • CORS (4.12.25, high, CVE-2026-54290): with credentials: true and origin unset/wildcard, affected versions reflected any Origin. Always set an explicit origin with credentials.
  • bodyLimit bypass for chunked/unknown-length bodies (4.12.16) and on AWS Lambda (4.12.25).
  • JWT: middleware accepted any Authorization scheme, not only Bearer (4.12.21); NumericDate claim validation (4.12.18).
  • Cache middleware ignored Vary: Authorization/Cookie (cross-user leak, 4.12.18).
  • hono/jsx SSR: several HTML/CSS injection and cross-request data disclosure issues (4.12.14 to 4.13.7), including memo() retaining output across requests (4.12.34).
  • serveStatic: Windows path traversal via %5C (4.12.25); double-decoding bypass of middleware on static paths (4.13.11).
  • parseBody() dot-notation memory exhaustion and query parsing after # (4.13.5); ReDoS in CORS and Language middleware (4.12.34).
  • AWS Lambda / Lambda@Edge / API Gateway adapters dropped repeated headers or merged Set-Cookie (4.12.25, 4.12.27).

New in 4.13.0

import { methodNotAllowed } from 'hono/method-not-allowed'
app.use(methodNotAllowed({ app }))         // 405 + Allow header
app.query('/search', async (c) => c.json(await search(await c.req.json())))

Gotchas introduced by 4.13.0:

  • Cache middleware key format changed for all methods (now /.hono/cache?__hono_cache_key=...). Code that calls caches.delete(originalUrl) must be updated.
  • CORS default allowMethods now includes QUERY.
  • RegExpRouter throws UnsupportedPathError at registration, not on first request.
  • JSX types aligned to React 19: RefObject<T> is { current: T }; use RefObject<T | null> and useRef(undefined).
  • JWT/JWK middleware accept a realm option; Compress sets Vary: Accept-Encoding.

Other recent APIs

  • 4.12.0: client.x.$path() returns a path string (vs $url()); ApplyGlobalResponse type for typing global error responses in the RPC client; SSG redirectPlugin.
  • 4.9.0: parseResponse() and DetailedError from hono/client to parse RPC responses and throw on non-OK.
  • 4.8.0: app.fire() deprecated - use import { fire } from 'hono/service-worker'; fire(app).

What to do now

Pin hono@^4.13.13, review CORS (origin + credentials), bodyLimit, JWT and cache middleware configs, and re-test any custom cache purging after upgrading past 4.13.0.

Sources