THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-crvj-82cr-hjcx (medium) — Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials

[GHSA] GHSA-crvj-82cr-hjcx (medium) — Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials

medgithub_advisoriesPublished 2026-09-08

GHSA-crvj-82cr-hjcx Severity: medium CVE: CVE-2026-84363

Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials

### Summary

Hono's query parsing does not stop at the URL fragment: a `?` appearing after a `#` is treated as the start of a query string. As a result, the application can read request parameters that no other component inv

Indicators of compromise

Original source: https://github.com/advisories/GHSA-crvj-82cr-hjcx