Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-84365Medium· 6.5Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix released for CVE-2026-39408 does not cover every traversal sequence, and toSSG() can still write files outside the c…
CVE-2026-84364Medium· 5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, when parseBody() expands dot-separated form field names into nested objects with dot-notation parsing enabled, it does not limit the n…
CVE-2026-84363Medium· 5.9Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, Hono's query helpers treat a question mark after a literal hash fragment as the start of a query string, so the application can read r…
CVE-2026-81888Medium· 5.4@hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is absent on both sides, so the anti-CSRF check passes for a ca…
CVE-2026-71848Medium· 5.3Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the languageDetector middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language ta…
CVE-2026-71849Low· 3.7Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy Helper proxy() function in hono/proxy does not remove response headers named by the origin's Connection header. Per RF…
CVE-2026-71850Medium· 4.8Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from hono/jsx retains the result of a server side render and reuses it for later renders with comparator equal props, and…
CVE-2026-69207Medium· 5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in CORS middleware, hono/cors, is vulnerable to a regular expression denial of service (ReDoS). During a preflight OPTIONS …
GHSA-9mqv-5hh9-4cggMedium· 5.3Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
GHSA-frvp-7c67-39w9Medium· 5.9Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
CVE-2026-59897Medium· 4.8Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
CVE-2026-59895Medium· 6.1Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
CVE-2026-59896Medium· 6.5hono/jsx does not isolate context per request, leading to cross-request data disclosure
CVE-2026-54287Medium· 5.3hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice
CVE-2026-54286Medium· 5.9hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
CVE-2026-54290High· 7.1hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard
CVE-2026-54289Medium· 4.8hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest
CVE-2026-54288Medium· 6.5hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.