Browse all 5 CVE security advisories affecting hono. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-56764 | Hono - Timing Attack in basicAuth and bearerAuth Middleware — HonoCWE-208 | 3.7 | Low | 2026-07-15 |
| CVE-2026-56763 | Hono - Prototype Pollution via __proto__ Key in parseBody with dot Option — HonoCWE-1321 | 4.8 | Medium | 2026-07-11 |
| CVE-2025-71381 | Hono - Vary Header Injection in CORS Middleware — HonoCWE-113 | 6.5 | Medium | 2026-06-30 |
| CVE-2026-56761 | hono - HTML Injection via Improper JSX Attribute Name Handling in SSR — honoCWE-79 | 4.3 | Medium | 2026-06-24 |
| CVE-2026-56762 | Hono - Missing Cookie Name Validation in setCookie() — HonoCWE-20 | 5.3 | Medium | 2026-06-23 |
This page lists every published CVE security advisory associated with hono. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.