50 Total advisories
50 Vulnerabilities
0 Malware

Dependency scanning

Check whether hono is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 4.8
npm

CVE-2026-71850

Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure

MEDIUM 5.3
npm

CVE-2026-69207

Hono: ReDoS in CORS middleware via Access-Control-Request-Headers

LOW 3.7
npm

CVE-2026-71849

Hono: Proxy Helper does not remove response headers listed in the `Connection` header

MEDIUM 6.1
npm

CVE-2026-59895

Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility

MEDIUM 5.3
npm

CVE-2026-47674

Hono: IP Restriction bypasses static deny rules for non-canonical IPv6

MEDIUM 5.3
npm

CVE-2026-47676

Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths

MEDIUM 5.3
npm

CVE-2026-44457

Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage

LOW 3.8
npm

CVE-2026-44459

Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()

UNKNOWN
npm

CVE-2026-39408

Hono: Path traversal in toSSG() allows writing files outside the output directory

MEDIUM 4.8
npm

CVE-2026-39410

Hono: Non-breaking space prefix bypass in cookie name handling in getCookie()

MEDIUM 5.3
npm

CVE-2026-24473

Hono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)

MEDIUM 4.8
npm

CVE-2026-24398

Hono IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing

HIGH 8.2
npm

CVE-2026-22818

Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback)

MEDIUM 5.0
npm

CVE-2024-43787

Hono CSRF middleware can be bypassed using crafted Content-Type header

MEDIUM 4.3
npm

CVE-2026-47675

Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection

MEDIUM 5.3
npm

CVE-2026-71848

Hono: Algorithmic Complexity DoS in Language Middleware

MEDIUM 4.8
npm

CVE-2026-59897

Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication

MEDIUM 5.9
npm

CVE-2026-54286

hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)

MEDIUM 4.8
npm

CVE-2026-54289

hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest

MEDIUM 6.5
npm

CVE-2026-54288

hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`

MEDIUM 5.3
npm

CVE-2026-54287

hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice

MEDIUM 4.8
npm

CVE-2026-47673

Hono: JWT middleware accepts any Authorization scheme, not only Bearer

HIGH 7.1
npm

CVE-2026-54290

hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard

MEDIUM 4.3
npm

CVE-2026-44458

Hono has CSS Declaration Injection via Style Object Values in JSX SSR

MEDIUM 6.5
npm

CVE-2026-44456

Hono: bodyLimit() can be bypassed for chunked / unknown-length requests

MEDIUM 4.7
npm

CVE-2026-44455

hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection

MEDIUM 5.3
npm

CVE-2026-39409

Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses

MEDIUM 5.3
npm

CVE-2026-39407

Hono: Middleware bypass via repeated slashes in serveStatic

MEDIUM 4.3
npm

CVE-2026-56761

hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR

MEDIUM 5.3
npm

CVE-2026-56762

Hono missing validation of cookie name on write path in setCookie()

MEDIUM 4.8
npm

CVE-2026-56763

Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })

HIGH 7.5
npm

CVE-2026-29045

Hono vulnerable to arbitrary file access via serveStatic vulnerability

MEDIUM 6.5
npm

CVE-2026-29085

Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE()

MEDIUM 5.4
npm

CVE-2026-29086

Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie()

HIGH 8.2
npm

CVE-2026-27700

Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo

LOW 3.7
npm

CVE-2026-56764

Hono added timing comparison hardening in basicAuth and bearerAuth

HIGH 8.2
npm

CVE-2026-22817

Hono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass

MEDIUM 4.7
npm

CVE-2026-24771

Hono vulnerable to XSS through ErrorBoundary component

MEDIUM 5.3
npm

CVE-2026-24472

Hono cache middleware ignores "Cache-Control: private" leading to Web Cache Deception

HIGH 8.1
npm

CVE-2025-62610

Hono Improper Authorization vulnerability

MEDIUM 5.3
npm

CVE-2025-59139

Hono has Body Limit Middleware Bypass

MEDIUM 5.9
npm

CVE-2024-48913

Hono allows bypass of CSRF Middleware by a request without Content-Type header.

MEDIUM 6.5
npm

CVE-2026-59896

hono/jsx does not isolate context per request, leading to cross-request data disclosure

MEDIUM 5.3
npm

CVE-2024-32869

Hono vulnerable to Restricted Directory Traversal in serveStatic with deno

MEDIUM 4.2
npm

CVE-2023-50710

Named path parameters can be overridden in TrieRouter

MEDIUM 5.3
npm

CVE-2026-84364

Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion

MEDIUM 6.5
npm

CVE-2026-84365

Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory

MEDIUM 5.9
npm

CVE-2026-84363

Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials

MEDIUM 4.2
npm

CVE-2025-71381

Hono vulnerable to Vary Header Injection leading to potential CORS Bypass

HIGH 7.5
npm

CVE-2025-58362

Hono's flaw in URL path parsing could cause path confusion

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes