Hono's IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, IP Restriction Middleware in Hono is vulnerable to an IP address validation bypass. The `IPV4_REGEX` pattern and `convertIPv4ToBinary` function in `src/utils/ipaddr.ts` do not properly validate that IPv4 octet values are within the valid range of 0-255, allowing attackers to craft malformed IP addresses that bypass IP-based access controls. Version 4.11.7 contains a patch for the issue.
References
-
https://github.com/honojs/hono/security/advisories/GHSA-r354-f388-2fhh x_refsource_CONFIRM
-
https://github.com/honojs/hono/releases/tag/v4.11.7 x_refsource_MISC
-
https://github.com/honojs/hono/security/advisories/GHSA-r354-f388-2fhh x_refsource_CONFIRM
-
https://github.com/honojs/hono/releases/tag/v4.11.7 x_refsource_MISC
-
https://github.com/honojs/hono/security/advisories/GHSA-r354-f388-2fhh x_refsource_CONFIRM
-
https://github.com/honojs/hono/releases/tag/v4.11.7 x_refsource_MISC
Affected products
- ==< 4.11.7
Matching in nixpkgs
pkgs.libsForQt5.phonon
Multimedia API for Qt
pkgs.kdePackages.phonon
Multi-platform sound framework for application developers
pkgs.kdePackages.phonon-vlc
VLC backend for the Phonon multimedia library
pkgs.plasma5Packages.phonon
Multimedia API for Qt
pkgs.python312Packages.phonopy
Modulefor phonon calculations at harmonic and quasi-harmonic levels
pkgs.python313Packages.phonopy
Modulefor phonon calculations at harmonic and quasi-harmonic levels
pkgs.libsForQt5.phonon-backend-vlc
GStreamer backend for Phonon
pkgs.python312Packages.pythonocc-core
Python wrapper for the OpenCASCADE 3D modeling kernel
pkgs.python313Packages.pythonocc-core
Python wrapper for the OpenCASCADE 3D modeling kernel
pkgs.plasma5Packages.phonon-backend-vlc
GStreamer backend for Phonon
pkgs.libsForQt5.phonon-backend-gstreamer
GStreamer backend for Phonon
pkgs.plasma5Packages.phonon-backend-gstreamer
GStreamer backend for Phonon
Package maintainers
-
@ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru>
-
@bkchr Bastian Köcher <nixos@kchr.de>
-
@SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
-
@nyanloutre Paul Trehiou <paul@nyanlout.re>
-
@K900 Ilya K. <me@0upti.me>
-
@FRidh Frederik Rietdijk <fridh@fridh.nl>
-
@SCOTT-HAMILTON Scott Hamilton <sgn.hamilton@protonmail.com>
-
@mjm Matt Moriarity <matt@mattmoriarity.com>
-
@NickCao Nick Cao <nickcao@nichi.co>
-
@peterhoeg Peter Hoeg <peter@hoeg.com>
-
@ttuegel Thomas Tuegel <ttuegel@mailbox.org>
-
@LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev>
-
@PsyanticY Psyanticy <iuns@outlook.fr>
-
@CHN-beta Haonan Chen <chn@chn.moe>