Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

hono — Vulnerabilities & Security Advisories 47

All 47 CVE vulnerabilities found in hono, with AI-generated Chinese analysis, references, and POCs.

This page details security vulnerabilities associated with the hono software product, specifically categorized under general weakness types and tagged for easy navigation. It aggregates a comprehensive list of disclosed security flaws, including buffer overflows, injection flaws, and configuration errors, covering data from the last ten years to provide a historical perspective on the product's security posture. By reviewing this collection, users can track vendor advisories to stay informed about emerging risks and patches, understand the specific implications of a given weakness class within the context of the hono framework, and look up a product's vulnerability history to assess long-term stability and maintenance trends. The content is structured to help developers, security analysts, and system administrators evaluate the impact of known issues and prioritize remediation efforts effectively. All listed vulnerabilities are sourced from verified databases and official vendor notices, ensuring accuracy and reliability for decision-making purposes. This resource serves as a central reference point for anyone needing to audit or secure deployments of hono, offering a clear view of past incidents and their resolutions without unnecessary noise or redundant information.

Vendor: honojs

CVE IDTitleCVSSSeverityPublished
CVE-2026-69207 Hono: ReDoS in CORS middleware via Access-Control-Request-Headers CWE-1333 5.3 Medium2026-08-07
CVE-2026-71850 Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure CWE-488 4.8 Medium2026-08-07
CVE-2026-71849 Hono: Proxy Helper does not remove response headers listed in the `Connection` header CWE-200 3.7 Low2026-08-07
CVE-2026-71848 Hono: Algorithmic Complexity DoS in Language Middleware CWE-407 5.3 Medium2026-08-07
CVE-2026-56764 Hono - Timing Attack in basicAuth and bearerAuth Middleware CWE-208 3.7 Low2026-07-15
CVE-2026-56763 Hono - Prototype Pollution via __proto__ Key in parseBody with dot Option CWE-1321 4.8 Medium2026-07-11
CVE-2026-59895 Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility CWE-79 6.1 Medium2026-07-08
CVE-2026-59896 hono/jsx does not isolate context per request, leading to cross-request data disclosure CWE-362 6.5 Medium2026-07-08
CVE-2026-59897 Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication CWE-348 4.8 Medium2026-07-08
CVE-2025-71381 Hono - Vary Header Injection in CORS Middleware CWE-113 6.5 Medium2026-06-30
CVE-2026-56761 hono - HTML Injection via Improper JSX Attribute Name Handling in SSR CWE-79 4.3 Medium2026-06-24
CVE-2026-56762 Hono - Missing Cookie Name Validation in setCookie() CWE-20 5.3 Medium2026-06-23
CVE-2026-54288 Hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length` CWE-345 6.5 Medium2026-06-22
CVE-2026-54289 Hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest CWE-348 4.8 Medium2026-06-22
CVE-2026-54290 Hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard CWE-942 7.1 High2026-06-22
CVE-2026-54286 Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) CWE-22 5.9 Medium2026-06-22
CVE-2026-54287 Hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice CWE-116 5.3 Medium2026-06-22
CVE-2026-47673 Hono: JWT middleware accepts any Authorization scheme, not only Bearer CWE-285 4.8 Medium2026-05-28
CVE-2026-47674 Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 CWE-185 5.3 Medium2026-05-28
CVE-2026-47675 Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection CWE-113 4.3 Medium2026-05-28
CVE-2026-47676 Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths CWE-444 5.3 Medium2026-05-28
CVE-2026-44459 Hono: Improper validation of NumericDate claims (exp, nbf, iat) in JWT verify() CWE-1284 3.8 Low2026-05-13
CVE-2026-44458 Hono: CSS Declaration Injection via Style Object Values in JSX SSR CWE-74 4.3 Medium2026-05-13
CVE-2026-44457 Hono: Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage CWE-524 5.3 Medium2026-05-13
CVE-2026-44456 Hono: bodyLimit() can be bypassed for chunked / unknown-length requests CWE-400 6.5 Medium2026-05-13
CVE-2026-44455 Hono: Unvalidated JSX Tag Names in hono/jsx May Allow HTML Injection CWE-74 4.7 Medium2026-05-13
CVE-2026-39410 Hono has a non-breaking space prefix bypass in cookie name handling in getCookie() CWE-20 4.8 Medium2026-04-08
CVE-2026-39409 Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses CWE-180 9.1AICriticalAI2026-04-08
CVE-2026-39408 Hono has a path traversal in toSSG() allows writing files outside the output directory CWE-22 7.5AIHighAI2026-04-08
CVE-2026-39407 Hono has a middleware bypass via repeated slashes in serveStatic CWE-22 5.3 Medium2026-04-08

All 47 known CVE vulnerabilities affecting hono with full Chinese analysis, references, and POCs where available.