hono vulnerabilities
CVEs whose affected-version data names the hono package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
16 CVEsRSS
CVE-2026-93981Medium· 4.7hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the roo…
hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the roo…
CVE-2026-84365Medium· 6.5Hono is a Web application framework that provides support for any JavaScript runtime
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix released for CVE-2026-39408 does not cover every traversal sequence, and toSSG() can still write files outside the c…
CVE-2026-84364Medium· 5.3Hono is a Web application framework that provides support for any JavaScript runtime
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, when parseBody() expands dot-separated form field names into nested objects with dot-notation parsing enabled, it does not limit the n…
CVE-2026-84363Medium· 5.9Hono is a Web application framework that provides support for any JavaScript runtime
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, Hono's query helpers treat a question mark after a literal hash fragment as the start of a query string, so the application can read r…
CVE-2026-71848Medium· 5.3Hono is a Web application framework that provides support for any JavaScript runtime
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the languageDetector middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language ta…
CVE-2026-71849Low· 3.7Hono is a Web application framework that provides support for any JavaScript runtime
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy Helper proxy() function in hono/proxy does not remove response headers named by the origin's Connection header. Per RF…
CVE-2026-71850Medium· 4.8Hono is a Web application framework that provides support for any JavaScript runtime
Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from hono/jsx retains the result of a server side render and reuses it for later renders with comparator equal props, and…
CVE-2026-69207Medium· 5.3Hono is a Web application framework that provides support for any JavaScript runtime
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in CORS middleware, hono/cors, is vulnerable to a regular expression denial of service (ReDoS). During a preflight OPTIONS …
CVE-2026-59897Medium· 4.8Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
CVE-2026-59895Medium· 6.1Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
CVE-2026-59896Medium· 6.5hono/jsx does not isolate context per request, leading to cross-request data disclosure
hono/jsx does not isolate context per request, leading to cross-request data disclosure
CVE-2026-54287Medium· 5.3hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice
hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice
CVE-2026-54286Medium· 5.9hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
CVE-2026-54290High· 7.1hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard
hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard
CVE-2026-54289Medium· 4.8hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest
hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest
CVE-2026-54288Medium· 6.5hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`