6 Total advisories
6 Vulnerabilities
0 Malware
Vulnerabilities
MEDIUM 5.9
GHSA-frvp-7c67-39w9
Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
MEDIUM 5.3
GHSA-9mqv-5hh9-4cgg
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
MEDIUM 5.3
CVE-2026-39406
@hono/node-server: Middleware bypass via repeated slashes in serveStatic
HIGH 7.5
CVE-2026-29087
@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware
HIGH 7.5
CVE-2024-32652
@hono/node-server has Denial of Service risk when receiving Host header that cannot be parsed
MEDIUM 5.3
CVE-2024-23340
@hono/node-server cannot handle "double dots" in URL
Ready to move
Start Securing
Free, no credit card | First findings in minutes