v4.13.11
Security fixes
serveStatic decodes the request path a second time, leading to bypass of middleware on static paths
Affects: hono/serve-static and the adapters built on it (hono/bun, hono/deno, hono/cloudflare-workers, @hono/bun, @hono/deno, @hono/cloudflare-workers). Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-5r4p-p66f-jhc7
serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.
The same fix ships in @hono/node-server v2.1.3.