PT-2026-4917 · Hono · Hono

Devanshbatham

·

Published

2026-01-27

·

Updated

2026-02-04

·

CVE-2026-24398

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Hono versions prior to 4.11.7
Description The IP Restriction Middleware in Hono does not properly validate IPv4 addresses, allowing attackers to bypass IP-based access controls. The IPV4 REGEX pattern and convertIPv4ToBinary function in src/utils/ipaddr.ts fail to ensure that IPv4 octet values are within the valid range of 0-255. This allows the creation of malformed IP addresses that circumvent intended restrictions.
Recommendations Update to version 4.11.7 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-24398
GHSA-R354-F388-2FHH

Affected Products

Hono