honojs hono是honojs的Web服务器。 honojs hono 4.12.25之前版本存在信任管理问题漏洞,该漏洞源于信任管理问题,可能导致重复请求标头被截断至单一值,从而削弱或改变访问控制决策。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54290 | 7.1 HIGH | Hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the w |
| CVE-2026-54288 | 6.5 MEDIUM | Hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length` |
| CVE-2026-54286 | 5.9 MEDIUM | Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) |
| CVE-2026-54287 | 5.3 MEDIUM | Hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping coo |
No comments yet