35 Total advisories
35 Vulnerabilities
0 Malware
Vulnerabilities
MEDIUM 4.3
CVE-2026-47675
Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection
MEDIUM 5.3
CVE-2026-47674
Hono: IP Restriction bypasses static deny rules for non-canonical IPv6
MEDIUM 5.3
CVE-2026-47676
Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths
MEDIUM 4.8
CVE-2026-47673
Hono: JWT middleware accepts any Authorization scheme, not only Bearer
MEDIUM 5.3
CVE-2026-44457
Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage
LOW 3.8
CVE-2026-44459
Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()
MEDIUM 6.5
CVE-2026-44456
Hono: bodyLimit() can be bypassed for chunked / unknown-length requests
MEDIUM 4.7
CVE-2026-44455
hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection
MEDIUM 4.3
CVE-2026-44458
Hono has CSS Declaration Injection via Style Object Values in JSX SSR
MEDIUM 5.3
CVE-2026-39409
Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses
MEDIUM 4.3
GHSA-458j-xx4x-4375
hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR
MEDIUM 5.3
GHSA-26pp-8wgv-hjvm
Hono missing validation of cookie name on write path in setCookie()
MEDIUM 4.8
CVE-2026-39410
Hono: Non-breaking space prefix bypass in cookie name handling in getCookie()
MEDIUM 5.3
CVE-2026-39407
Hono: Middleware bypass via repeated slashes in serveStatic
UNKNOWN
CVE-2026-39408
Hono: Path traversal in toSSG() allows writing files outside the output directory
MEDIUM 4.2
CVE-2023-50710
Named path parameters can be overridden in TrieRouter
MEDIUM 5.0
CVE-2024-43787
Hono CSRF middleware can be bypassed using crafted Content-Type header
HIGH 8.1
CVE-2025-62610
Hono Improper Authorization vulnerability
MEDIUM 5.9
CVE-2024-48913
Hono allows bypass of CSRF Middleware by a request without Content-Type header.
MEDIUM 5.3
CVE-2025-59139
Hono has Body Limit Middleware Bypass
MEDIUM 5.3
CVE-2024-32869
Hono vulnerable to Restricted Directory Traversal in serveStatic with deno
MEDIUM 5.4
CVE-2026-29086
Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie()
MEDIUM 6.5
CVE-2026-29085
Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE()
HIGH 7.5
CVE-2026-29045
Hono vulnerable to arbitrary file access via serveStatic vulnerability
MEDIUM 4.8
GHSA-v8w9-8mx6-g223
Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })
HIGH 8.2
CVE-2026-27700
Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo
LOW 3.7
GHSA-gq3j-xvxp-8hrf
Hono added timing comparison hardening in basicAuth and bearerAuth
MEDIUM 4.8
CVE-2026-24398
Hono IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing
MEDIUM 4.7
CVE-2026-24771
Hono vulnerable to XSS through ErrorBoundary component
MEDIUM 5.3
CVE-2026-24473
Hono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)
MEDIUM 5.3
CVE-2026-24472
Hono cache middleware ignores "Cache-Control: private" leading to Web Cache Deception
HIGH 8.2
CVE-2026-22817
Hono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass
HIGH 8.2
CVE-2026-22818
Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback)
MEDIUM 4.2
GHSA-q7jf-gf43-6x6p
Hono vulnerable to Vary Header Injection leading to potential CORS Bypass
HIGH 7.5
CVE-2025-58362
Hono's flaw in URL path parsing could cause path confusion
Ready to move
Start Securing
Free, no credit card | First findings in minutes