| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| README.md | 2026-09-29 | 712 Bytes | |
| v4.13.11 source code.tar.gz | 2026-09-29 | 1.8 MB | |
| v4.13.11 source code.zip | 2026-09-29 | 2.0 MB | |
| Totals: 3 Items | 3.7 MB | 0 | |
Security fixes
serveStatic decodes the request path a second time, leading to bypass of middleware on static paths
Affects: hono/serve-static and the adapters built on it (hono/bun, hono/deno, hono/cloudflare-workers, @hono/bun, @hono/deno, @hono/cloudflare-workers). Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-5r4p-p66f-jhc7
serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.
The same fix ships in @hono/node-server v2.1.3.