Echo: hono: security update to 4.12.34

medium Tenable Self-Hosted Container Security Plugin ID 464461

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to
4.12.33, memo() from hono/jsx retains the result of a server side render and reuses it for later renders
with comparator equal props, and request scoped values read inside the component take no part in that
comparison, so a response can contain HTML rendered for another user's request. Components wrapped with
memo() are compared by props alone; values read implicitly during rendering, such as JSX Context through
createContext() and useContext(), useRequestContext() from hono/jsx-renderer, and getContext() from
hono/context-storage, do not participate, and the retained result lives as long as the wrapped component,
so it outlives the request that produced it. A user may receive a response containing HTML rendered for
another user when both render the same memoized component with comparator equal props on the same warm
instance, which may disclose another user's account or profile data, disclose request scoped secrets
embedded in HTML such as CSRF tokens, or expose role specific content to users who should not receive it.
This issue is fixed in version 4.12.34. (CVE-2026-71850)

Solution

Update the hono library and its related packages to version 4.12.34 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-71850

Plugin Details

Severity: Medium

ID: 464461

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.76

CVSS v2

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 3.6

Vector: CVSS2#AV:N/AC:H/Au:S/C:C/I:N/A:N

CVSS Score Source: CVE-2026-71850

CVSS v3

Risk Factor: Medium

Base Score: 4.8

Temporal Score: 4.2

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 8/7/2026

Reference Information

CVE: CVE-2026-71850