This release includes 3 security fixes for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
ReleasePort's take
Moderate signalRelease v3.1.26 patches three critical security issues: an axios proxy‑auth redirect leak (CVE-2026-44486/87), a Hono setCookie attribute injection flaw (CVE-2026-47675), and a Drizzle SQL injection vulnerability.
Why it matters: All listed CVEs have high severity; immediate patching prevents information leakage, cookie hijacking, and SQL injection attacks. Deploy v3.1.26 to mitigate these risks.
Summary
AI summaryFixes CVE-2026-44486/87, CVE-2026-47675 and a Drizzle SQL injection vulnerability.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes axios proxy-auth redirect information leak (CVE-2026-44486/87). Fixes axios proxy-auth redirect information leak (CVE-2026-44486/87). Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Security | Critical |
Fixes hono setCookie attribute injection vulnerability (CVE-2026-47675). Fixes hono setCookie attribute injection vulnerability (CVE-2026-47675). Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Security | Critical |
Addresses Miasma @redhat-cloud-services namespace IOC issue (RHSB-2026-006). Addresses Miasma @redhat-cloud-services namespace IOC issue (RHSB-2026-006). Source: llm_adapter@2026-06-06 Confidence: high |
— |
| Dependency | Medium |
Patches hono, brace-expansion, and qs via npm audit fix. Patches hono, brace-expansion, and qs via npm audit fix. Source: llm_adapter@2026-06-06 Confidence: high |
— |
Full changelog
- VG1071-1073: axios proxy-auth redirect leak (CVE-2026-44486/87), hono setCookie attribute injection (CVE-2026-47675), drizzle sql.raw/sql.identifier interpolation
- VG1074-1075: Miasma @redhat-cloud-services namespace IOC (RHSB-2026-006), Session messenger filev2.getsession.org exfil endpoint
- npm audit fix: hono / brace-expansion / qs patched; hono override floor bumped to ^4.12.21; self-audit PASS A 100
Security Fixes
- CVE-2026-44486 — axios proxy‑auth redirect leak
- CVE-2026-44487 — axios proxy‑auth redirect leak (second variant)
- CVE-2026-47675 — Hono setCookie attribute injection
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Related context
Related tools
Beta — feedback welcome: [email protected]