Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

hono — Vulnerabilities & Security Advisories 51

All 51 CVE vulnerabilities found in hono, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerability data for the hono product, focusing on software weaknesses within the HTTP framework ecosystem. It collects historical and recent security advisories related to hono, covering a defined time range of published reports. Here, you can track the vendor's published advisories, analyze the prevalence of specific weakness classes, and review the product's cumulative vulnerability history. The content is organized to facilitate rapid identification of affected components and associated risk levels without requiring external cross-referencing.

Vendor: honojs

CVE ID Title CVSS Severity Published
CVE-2026-93981 hono/jsx before 4.13.7 Cross-Site Scripting via Unescaped Strings CWE-79 4.7 Medium 2026-09-19
CVE-2026-84365 Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory CWE-22 6.5 Medium 2026-09-01
CVE-2026-84364 Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion CWE-400 5.3 Medium 2026-09-01
CVE-2026-84363 Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials CWE-444 5.9 Medium 2026-09-01
CVE-2026-69207 Hono: ReDoS in CORS middleware via Access-Control-Request-Headers CWE-1333 5.3 Medium 2026-08-07
CVE-2026-71850 Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure CWE-488 4.8 Medium 2026-08-07
CVE-2026-71849 Hono: Proxy Helper does not remove response headers listed in the `Connection` header CWE-200 3.7 Low 2026-08-07
CVE-2026-71848 Hono: Algorithmic Complexity DoS in Language Middleware CWE-407 5.3 Medium 2026-08-07
CVE-2026-56764 Hono - Timing Attack in basicAuth and bearerAuth Middleware CWE-208 3.7 Low 2026-07-15
CVE-2026-56763 Hono - Prototype Pollution via __proto__ Key in parseBody with dot Option CWE-1321 4.8 Medium 2026-07-11
CVE-2026-59895 Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility CWE-79 6.1 Medium 2026-07-08
CVE-2026-59896 hono/jsx does not isolate context per request, leading to cross-request data disclosure CWE-362 6.5 Medium 2026-07-08
CVE-2026-59897 Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication CWE-348 4.8 Medium 2026-07-08
CVE-2025-71381 Hono - Vary Header Injection in CORS Middleware CWE-113 6.5 Medium 2026-06-30
CVE-2026-56761 hono - HTML Injection via Improper JSX Attribute Name Handling in SSR CWE-79 4.3 Medium 2026-06-24
CVE-2026-56762 Hono - Missing Cookie Name Validation in setCookie() CWE-20 5.3 Medium 2026-06-23
CVE-2026-54288 Hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length` CWE-345 6.5 Medium 2026-06-22
CVE-2026-54289 Hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest CWE-348 4.8 Medium 2026-06-22
CVE-2026-54290 Hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard CWE-942 7.1 High 2026-06-22
CVE-2026-54286 Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) CWE-22 5.9 Medium 2026-06-22
CVE-2026-54287 Hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice CWE-116 5.3 Medium 2026-06-22
CVE-2026-47673 Hono: JWT middleware accepts any Authorization scheme, not only Bearer CWE-285 4.8 Medium 2026-05-28
CVE-2026-47674 Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 CWE-185 5.3 Medium 2026-05-28
CVE-2026-47675 Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection CWE-113 4.3 Medium 2026-05-28
CVE-2026-47676 Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths CWE-444 5.3 Medium 2026-05-28
CVE-2026-44459 Hono: Improper validation of NumericDate claims (exp, nbf, iat) in JWT verify() CWE-1284 3.8 Low 2026-05-13
CVE-2026-44458 Hono: CSS Declaration Injection via Style Object Values in JSX SSR CWE-74 4.3 Medium 2026-05-13
CVE-2026-44457 Hono: Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage CWE-524 5.3 Medium 2026-05-13
CVE-2026-44456 Hono: bodyLimit() can be bypassed for chunked / unknown-length requests CWE-400 6.5 Medium 2026-05-13
CVE-2026-44455 Hono: Unvalidated JSX Tag Names in hono/jsx May Allow HTML Injection CWE-74 4.7 Medium 2026-05-13

All 51 known CVE vulnerabilities affecting hono with full Chinese analysis, references, and POCs where available.