What is CVE-2026-71848?
CVE-2026-71848 affects Hono web framework's languageDetector middleware from version 4.12.0 to 4.12.33. It is vulnerable to algorithmic complexity denial of service when processing a crafted language tag with many hyphen-separated subtags. Developers should immediately update their Hono version.
Azərbaycanca: CVE-2026-71848 Hono veb framework-inin languageDetector middleware-də aşkarlanıb. 4.12.0-dən 4.12.33-ə qədər versiyalarda, çoxlu defislə ayrılmış alt teqlər olan xüsusi hazırlanmış dil teqi emal edilərkən alqoritmik mürəkkəblik DoS zəifliyi yaranır. Tərtibatçılar Hono versiyasını təcili yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which functionality of Hono framework is targeted by CVE-2026-71848?
This vulnerability is detected in the languageDetector middleware of the Hono web framework.
How is an attack exploiting CVE-2026-71848 carried out?
The attack is carried out by exploiting algorithmic complexity during the processing of a specially crafted language tag containing many hyphen-separated subtags, causing a denial of service (DoS).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.