fix(deps): update dependency @hono/node-server to v2 [security]#2727
Open
renovate[bot] wants to merge 1 commit into
Open
fix(deps): update dependency @hono/node-server to v2 [security]#2727renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 22, 2026 00:08
477bdeb to
fae94b8
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 22, 2026 00:38
fae94b8 to
9158487
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 22, 2026 21:47
9158487 to
fda3d1c
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 22, 2026 22:46
fda3d1c to
7b652e2
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 23, 2026 00:50
7b652e2 to
19a0264
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 23, 2026 01:20
19a0264 to
75997dc
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 23, 2026 01:24
75997dc to
7258c3c
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 23, 2026 03:01
7258c3c to
3c8a11b
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 23, 2026 07:04
3c8a11b to
a351895
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
2 times, most recently
from
July 23, 2026 14:48
900993a to
000403e
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 23, 2026 15:36
000403e to
4f7b227
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 23, 2026 17:42
4f7b227 to
23220fb
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 23, 2026 19:06
23220fb to
1c63f4b
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 23, 2026 21:32
1c63f4b to
de38695
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 24, 2026 07:11
465c170 to
9f47cc8
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 24, 2026 15:23
9f47cc8 to
ca09850
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 24, 2026 15:39
ca09850 to
10bd140
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 24, 2026 17:02
10bd140 to
0433d92
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 24, 2026 18:22
0433d92 to
a0af342
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 24, 2026 18:58
a0af342 to
4be0400
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 25, 2026 01:46
4be0400 to
1ebe41a
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 25, 2026 02:35
1ebe41a to
0c80f6f
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 25, 2026 05:12
0c80f6f to
562eec3
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 25, 2026 07:35
562eec3 to
e8458c6
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 25, 2026 08:45
e8458c6 to
db18036
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 25, 2026 12:35
db18036 to
cd20811
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 25, 2026 16:09
cd20811 to
bf56a40
Compare
renovate
Bot
force-pushed
the
renovate/npm-hono-node-server-vulnerability
branch
from
July 25, 2026 17:05
bf56a40 to
773d1e4
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^1.13.0→^2.0.5^1.8.0→^2.0.5Node.js Adapter for Hono: Path traversal in
serve-staticon Windows via encoded backslash (%5C)GHSA-frvp-7c67-39w9
More information
Details
The same as the
honocore Path traversal inserve-staticon Windows via encoded backslash (%5C).Summary
On Windows hosts, an encoded backslash (
%5C) in the request path decodes to\, which the Windows path resolver treats as a separator.serve-staticthen resolves a single URL segment such asadmin\secret.txtinto a nested file under the root and serves it, letting an attacker read static files meant to be protected behind prefix-mounted middleware. Directory escape (..) remains blocked.Details
The router splits paths only on
/, so/admin%5Csecret.txtis one segment and middleware on/admin/*does not run. Theserve-staticguard rejects./..and consecutive separators but lets a lone\through; on Windows the file resolver re-splits it into the protected subtree.This affects Windows hosts serving static files via the Node, Bun, or Deno adapters that guard a static subtree with prefix-mounted middleware.
Impact
An unauthenticated attacker can read static files under a middleware-guarded prefix on Windows hosts. The read stays within the configured root; escape outside the root is not possible.
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
honojs/node-server (@hono/node-server)
v2.0.5Compare Source
Security Fix
Fixed a security issue in Serve Static Middleware where prefix-mounted middleware could be bypassed on Windows. This only affects applications running on Windows that use Serve Static Middleware. Affected users are encouraged to upgrade to this version.
See GHSA-frvp-7c67-39w9 for details.
v2.0.4Compare Source
What's Changed
Full Changelog: honojs/node-server@v2.0.3...v2.0.4
v2.0.3Compare Source
What's Changed
ServeStaticOptionscomment with the current spec by @kakkokari-gtyih in #356New Contributors
Full Changelog: honojs/node-server@v2.0.2...v2.0.3
v2.0.2Compare Source
What's Changed
Full Changelog: honojs/node-server@v2.0.1...v2.0.2
v2.0.1Compare Source
What's Changed
New Contributors
Full Changelog: honojs/node-server@v2.0.0...v2.0.1
v2.0.0Compare Source
Now, we release the second major version of the Hono Node.js adapter 🎉 🎉 🎉
The Hono Node.js adapter is now up to 2.3x faster
v2 of the Hono Node.js adapter reaches up to 2.3x the throughput of v1 — that's the peak number, measured on the body-parsing scenario of
bun-http-framework-benchmark. The other scenarios (Ping, Query) get a smaller but real boost too.Install or upgrade with:
v2
The Node.js adapter is going through a major version bump to v2. That said, the public API stays the same — the headline of this release is the large performance improvement described above.
What does the Node.js adapter do?
A quick refresher on what the Node.js adapter actually does — it exists so that Hono applications can run on Node.js. Hono is built on the Web Standards APIs, but you cannot serve those directly from Node.js. The adapter bridges the Web Standards APIs and the Node.js APIs, which is what lets a Hono app — and more generally a Web-Standards-style app — run on top of Node.js.
If you write the following code and run
node ./index.js, a server starts up onlocalhost:3000. And it really is plain Node.js underneath.The early performance story
The very first implementation of the Node.js adapter looked roughly like this in pseudocode:
So the flow was:
IncomingMessageRequestobject and handed to the appResponsereturned by the app is written back to the outgoingServerResponseIn diagram form:
This is, frankly, inefficient. So whenever Hono went head-to-head with other Node.js frameworks we kept losing — all we could do was shrug and say "well, it's slow on Node.js."
Introducing LightweightRequest / LightweightResponse
The huge step forward that fixed this was a legendary PR from @usualoma:
#95
It made things up to 2.7x faster.
I previously wrote about this in detail in this post:
https://zenn.dev/yusukebe/articles/7ac501716ae1f7?locale=en
In short, the trick is wonderfully simple. It just follows the golden rule of performance tuning: don't do work you don't have to do. Lightweight versions of
RequestandResponseare constructed and used first — and that path is fast. Only when something actually needs the contents of theRequest, e.g. when you callreq.json(), does a realnew Request()get instantiated under the hood and used from then on. The result is fast, and behavior stays correct.…but body parsing was still slow
"Fast" here was for a very simple "Hello World" benchmark — a GET that just returns text.
There are many ways to benchmark, but the one we tend to reach for is this:
https://github.com/SaltyAom/bun-http-framework-benchmark
It tests three scenarios: Ping, Query, and Body. Let's pit Hono against the major Node.js frameworks:
As you can see, the Body case is very slow. The handler being measured is essentially this:
c.req.json()is the slow part. The reason is well understood: inside the Node.js adapter, whenjson()is called the LightweightRequest path can't be used, so a realnew Request()ends up being constructed.perf: optimize request body reading
The 2.3x figure above comes from one PR specifically — PR #301 by @mgcrea:
The PR bundles a few changes, but the key one is "optimize request body reading". Quoting from the PR description:
In other words, in the
json()case above, we no longer convert into aRequestat all — we read the body straight off the Node.js APIs. A classic fast path. That alone gives a large jump in body-parsing throughput.The same PR also includes two other tuning improvements:
URLobject except in edge casesbuildOutgoingHttpHeadersoptimization — skip theset-cookieheader comparison when there are no cookiesv2 ships several other performance PRs as well —
newHeadersFromIncomingand signal fast-paths,Responsefast-paths andresponseViaCacheimprovements, method-key caching, a regex-basedbuildUrlrewrite, and more (see the full list below). They all add up, but #301 is by far the largest single contributor, which is why it gets the spotlight here.v2 performance
Now let's measure the final v2 build.
First, comparing against the v1 Node.js adapter.
devhere is v2. Body improves by 2.3x, and the other scenarios get faster too:Next, the same comparison against other frameworks. With the Body score jumping, Hono passes Koa and Fastify and takes first place:
Breaking changes
There are two breaking changes in v2.
Dropped support for Node.js v18
Node.js v18 reached end-of-life, so v2 requires Node.js v20 or later.
Removed the Vercel adapter
The Vercel adapter (
@hono/node-server/vercel) has been removed. It is no longer needed for Vercel's modern runtimes, so the recommendation is to deploy without it.If you still need the previous behavior, the old adapter was a one-liner on top of
getRequestListenerand you can write the same thing in your own project:Then use it the same way you used
handlefrom@hono/node-server/vercelbefore.All changes
A full list of what landed in PR #316.
Performance
buildOutgoingHttpHeadersfor the common case (#301) by @mgcrea:as safe host (#320) by @yusukebenewHeadersFromIncomingand signal fast-path (#332) by @GavinMeierSonosResponsefast-paths andresponseViaCacheimprovements (#333) by @GavinMeierSonosUint8Arraylookup tables with regex inbuildUrl(#345) by @usualomaFeatures
Breaking changes
Fixes & refactors
new URL()should be used (#310) by @usualomaRequestobject (#311) by @usualomaBlob/ReadableStreamcacheable responses (#342) by @usualomaResponse.json()andResponse.redirect()spec compliance and efficiency (#343) by @usualomaBuild & tooling
type: moduletopackage.json(#336) by @yusukebeWrap-up
So that's v2 of the Node.js adapter — significantly faster, with the same API. Just upgrading should give you a real performance boost. No more "Hono is slow on Node.js" excuses. Please use Hono — fast not only on Cloudflare, Bun, and Deno, but now also on Node.js.
v1.19.15Compare Source
v1.19.14Compare Source
What's Changed
Full Changelog: honojs/node-server@v1.19.13...v1.19.14
v1.19.13Compare Source
Security Fix
Fixed an issue in Serve Static Middleware where inconsistent handling of repeated slashes (
//) between the router and static file resolution could allow middleware to be bypassed. Users of Serve Static Middleware are encouraged to upgrade to this version.See GHSA-92pp-h63x-v22m for details.
v1.19.12Compare Source
What's Changed
Full Changelog: honojs/node-server@v1.19.11...v1.19.12
v1.19.11Compare Source
What's Changed
Full Changelog: honojs/node-server@v1.19.10...v1.19.11
v1.19.10Compare Source
Security Fix
Fixed an authorization bypass in Serve Static Middleware caused by inconsistent URL decoding (
%2Fhandling) between the router and static file resolution. Users of Serve Static Middleware are encouraged to upgrade to this version.See GHSA-wc8c-qw6v-h7f6 for details.
v1.19.9Compare Source
What's Changed
Full Changelog: honojs/node-server@v1.19.8...v1.19.9
v1.19.8Compare Source
What's Changed
New Contributors
Full Changelog: honojs/node-server@v1.19.7...v1.19.8
v1.19.7Compare Source
What's Changed
configVersionto bun.lock by @yusukebe in #291New Contributors
Full Changelog: honojs/node-server@v1.19.6...v1.19.7
v1.19.6Compare Source
What's Changed
Full Changelog: honojs/node-server@v1.19.5...v1.19.6
v1.19.5Compare Source
What's Changed
Full Changelog: honojs/node-server@v1.19.4...v1.19.5
v1.19.4Compare Source
What's Changed
New Contributors
Full Changelog: honojs/node-server@v1.19.3...v1.19.4
v1.19.3Compare Source
What's Changed
New Contributors
Full Changelog: honojs/node-server@v1.19.2...v1.19.3
v1.19.2Compare Source
What's Changed
New Contributors
Full Changelog: honojs/node-server@v1.19.1...v1.19.2
v1.19.1Compare Source
What's Changed
packageManagerfield inpackage.jsonby @yusukebe in #275Full Changelog: honojs/node-server@v1.19.0...v1.19.1
v1.19.0Compare Source
What's Changed
New Contributors
Full Changelog: honojs/node-server@v1.18.2...v1.19.0
v1.18.2Compare Source
What's Changed
Full Changelog: honojs/node-server@v1.18.1...v1.18.2
v1.18.1Compare Source
What's Changed
Full Changelog: honojs/node-server@v1.18.0...v1.18.1
v1.18.0Compare Source
What's Changed
res.bodyby @usualoma in #262v24for CI by @yusukebe in #263Full Changelog: honojs/node-server@v1.17.1...v1.18.0
v1.17.1Compare Source
What's Changed
Full Changelog: honojs/node-server@v1.17.0...v1.17.1
v1.17.0Compare Source
What's Changed
server_socket.test.tstoserver-socket.test.tsby @yusukebe in #256Full Changelog: honojs/node-server@v1.16.0...v1.17.0
v1.16.0Compare Source
What's Changed
Full Changelog: honojs/node-server@v1.15.0...v1.16.0
v1.15.0Compare Source
What's Changed
rewriteRequestPathby @yusukebe in #247Full Changelog: honojs/node-server@v1.14.4...v1.15.0
v1.14.4Compare Source
What's Changed
Full Changelog: honojs/node-server@v1.14.3...v1.14.4
v1.14.3Compare Source
What's Changed
RequestErrorname properly by @yusukebe in #243Full Changelog: honojs/node-server@v1.14.2...v1.14.3
v1.14.2Compare Source
What's Changed
headers,status, andok, and then drop thegetInternalBodyfunction. by @usualoma in #242Full Changelog: honojs/node-server@v1.14.1...v1.14.2
v1.14.1Compare Source
What's Changed
New Contributors
Full Changelog: honojs/node-server@v1.14.0...v1.14.1
v1.14.0Compare Source
What's Changed
responseViaCacheby @yusukebe in #234New Contributors
Full Changelog: honojs/node-server@v1.13.8...v1.14.0
v1.13.8Compare Source
What's Changed
incoming.rawBodyif available by @usualoma in #223New Contributors
Full Changelog: honojs/node-server@v1.13.7...v1.13.8
v1.13.7Compare Source
What's Changed
New Contributors
Full Changelog: honojs/node-server@v1.13.6...v1.13.7
v1.13.6Compare Source
What's Changed
Full Changelog: honojs/node-server@v1.13.5...v1.13.6
v1.13.5Compare Source
What's Changed
Full Changelog: honojs/node-server@v1.13.4...v1.13.5
v1.13.4Compare Source
What's Changed
New Contributors
Full Changelog: honojs/node-server@v1.13.3...v1.13.4
v1.13.3Compare Source
What's Changed
New Contributors
Full Changelog: honojs/node-server@v1.13.2...v1.13.3
v1.13.2Compare Source
What's Changed
New Contributors
Full Changelog: honojs/node-server@v1.13.1...v1.13.2
v1.13.1Compare Source
What's Changed
Full Changelog: honojs/node-server@v1.13.0...v1.13.1
Configuration
📅 Schedule: (in timezone America/Los_Angeles)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.