{"id":"CVE-2026-39409","aliases":["GHSA-xpcf-pg52-r92g"],"url":"https://o3.security/vulnerability/CVE-2026-39409","summary":"Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses","details":"Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() does not canonicalize IPv4-mapped IPv6 client addresses (e.g. ::ffff:127.0.0.1) before applying IPv4 allow or deny rules. In environments such as Node.js dual-stack, this can cause IPv4 rules to fail to match, leading to unintended authorization behavior. This vulnerability is fixed in 4.12.12.","published":"2026-04-08T14:43:36.476Z","modified":"2026-08-07T11:50:16.494985919Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"hono","fixedVersion":"4.12.12"}],"fix":{"url":"https://github.com/honojs/hono/commit/48fa2233bc092f650119f42df043050737cabf39","label":"honojs/hono@48fa223"},"references":[{"type":"WEB","url":"https://github.com/honojs/hono/releases/tag/v4.12.12"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39409.json"},{"type":"ADVISORY","url":"https://github.com/honojs/hono/security/advisories/GHSA-xpcf-pg52-r92g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39409"},{"type":"FIX","url":"https://github.com/honojs/hono/commit/48fa2233bc092f650119f42df043050737cabf39"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:50:16.494985919Z"}}