Dependency scanning
Check whether hono is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-71850
Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
CVE-2026-69207
Hono: ReDoS in CORS middleware via Access-Control-Request-Headers
CVE-2026-71849
Hono: Proxy Helper does not remove response headers listed in the `Connection` header
CVE-2026-59895
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
CVE-2026-47674
Hono: IP Restriction bypasses static deny rules for non-canonical IPv6
CVE-2026-47676
Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths
CVE-2026-44457
Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage
CVE-2026-44459
Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()
CVE-2026-39408
Hono: Path traversal in toSSG() allows writing files outside the output directory
CVE-2026-39410
Hono: Non-breaking space prefix bypass in cookie name handling in getCookie()
CVE-2026-24473
Hono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)
CVE-2026-24398
Hono IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing
CVE-2026-22818
Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback)
CVE-2024-43787
Hono CSRF middleware can be bypassed using crafted Content-Type header
CVE-2026-47675
Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection
CVE-2026-71848
Hono: Algorithmic Complexity DoS in Language Middleware
CVE-2026-59897
Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
CVE-2026-54286
hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
CVE-2026-54289
hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest
CVE-2026-54288
hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
CVE-2026-54287
hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice
CVE-2026-47673
Hono: JWT middleware accepts any Authorization scheme, not only Bearer
CVE-2026-54290
hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard
CVE-2026-44458
Hono has CSS Declaration Injection via Style Object Values in JSX SSR
CVE-2026-44456
Hono: bodyLimit() can be bypassed for chunked / unknown-length requests
CVE-2026-44455
hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection
CVE-2026-39409
Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses
CVE-2026-39407
Hono: Middleware bypass via repeated slashes in serveStatic
CVE-2026-56761
hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR
CVE-2026-56762
Hono missing validation of cookie name on write path in setCookie()
CVE-2026-56763
Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })
CVE-2026-29045
Hono vulnerable to arbitrary file access via serveStatic vulnerability
CVE-2026-29085
Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE()
CVE-2026-29086
Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie()
CVE-2026-27700
Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo
CVE-2026-56764
Hono added timing comparison hardening in basicAuth and bearerAuth
CVE-2026-22817
Hono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass
CVE-2026-24771
Hono vulnerable to XSS through ErrorBoundary component
CVE-2026-24472
Hono cache middleware ignores "Cache-Control: private" leading to Web Cache Deception
CVE-2025-62610
Hono Improper Authorization vulnerability
CVE-2025-59139
Hono has Body Limit Middleware Bypass
CVE-2024-48913
Hono allows bypass of CSRF Middleware by a request without Content-Type header.
CVE-2026-59896
hono/jsx does not isolate context per request, leading to cross-request data disclosure
CVE-2024-32869
Hono vulnerable to Restricted Directory Traversal in serveStatic with deno
CVE-2023-50710
Named path parameters can be overridden in TrieRouter
CVE-2026-84364
Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion
CVE-2026-84365
Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory
CVE-2026-84363
Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials
CVE-2025-71381
Hono vulnerable to Vary Header Injection leading to potential CORS Bypass
CVE-2025-58362
Hono's flaw in URL path parsing could cause path confusion
Browse more npm advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes