Releases: honojs/node-server
Release list
v2.1.3
Security fixes
serveStatic decodes the request path a second time, leading to bypass of middleware on static paths
Affects: @hono/node-server/serve-static. Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-rmxm-3fg6-px4f
serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.
The same fix ships in hono v4.13.11.
v2.1.2
What's Changed
- ci: add autofix.ci by @yusukebe in #392
- fix: type error in early hints and add typecheck to CI by @BlankParticle in #390
- chore: add better benchmarks by @BlankParticle in #391
- docs(readme): update the benchmark by @yusukebe in #394
- test(request): accept asynchronous body read errors by @usualoma in #403
- fix(listener): avoid mutating response headers when setting Content-Length by @usualoma in #402
Full Changelog: v2.1.1...v2.1.2
v2.1.1
What's Changed
- perf: lazily materialize request headers by @BlankParticle in #389
Full Changelog: v2.1.0...v2.1.1
v2.1.0
What's Changed
- feat: add Early Hints (HTTP 103) middleware by @bilal-azam in #378
- fix(listener): avoid uncaught error when force-closing a non-standard socket by @mohamedramadan14 in #383
New Contributors
- @bilal-azam made their first contribution in #378
- @mohamedramadan14 made their first contribution in #383
Full Changelog: v2.0.12...v2.1.0
v1.19.17
v2.0.12
What's Changed
- test: replace supertest by @BlankParticle in #379
- fix(response): copy headers when init is a foreign Response by @yusukebe in #382
Full Changelog: v2.0.11...v2.0.12
v2.0.11
What's Changed
- test: use a custom helper for path traversal tests by @BlankParticle in #377
- perf(request): fast-path QUERY methods by @usualoma in #376
- perf(request): fast-path PATCH method by @yusukebe in #380
Full Changelog: v2.0.10...v2.0.11
v2.0.10
Security fixes
This release includes a fix for the following security issue:
Unauthenticated memory-leak DoS via aborted WebSocket handshake
Affects: upgradeWebSocket. A WebSocket upgrade request with a missing or malformed Sec-WebSocket-Key header leaked the request's IncomingMessage and left a promise pending, even though no connection was established. Since the route is reachable pre-handshake without authentication, an attacker could flood it to gradually exhaust memory. GHSA-9mqv-5hh9-4cgg
Users of upgradeWebSocket are encouraged to upgrade to this version.