VulnSea

hono vulnerabilities

CVEs whose affected-version data names the hono package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

16 CVEsRSS

CVE-2026-93981Medium· 4.7
3d ago

hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the roo…

hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the roo…

Sunlithonojs · honoEPSS 0.14%via NVD
CVE-2026-84365Medium· 6.5
3w ago

Hono is a Web application framework that provides support for any JavaScript runtime

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix released for CVE-2026-39408 does not cover every traversal sequence, and toSSG() can still write files outside the c…

Sunlithono · honoEPSS 0.33%via NVD
CVE-2026-84364Medium· 5.3
3w ago

Hono is a Web application framework that provides support for any JavaScript runtime

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, when parseBody() expands dot-separated form field names into nested objects with dot-notation parsing enabled, it does not limit the n…

Sunlithono · honoEPSS 0.39%via NVD
CVE-2026-84363Medium· 5.9
3w ago

Hono is a Web application framework that provides support for any JavaScript runtime

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, Hono's query helpers treat a question mark after a literal hash fragment as the start of a query string, so the application can read r…

Sunlithono · honoEPSS 0.34%via NVD
CVE-2026-71848Medium· 5.3
1mo ago

Hono is a Web application framework that provides support for any JavaScript runtime

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the languageDetector middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language ta…

Sunlithono · honoEPSS 0.29%via NVD
CVE-2026-71849Low· 3.7
1mo ago

Hono is a Web application framework that provides support for any JavaScript runtime

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy Helper proxy() function in hono/proxy does not remove response headers named by the origin's Connection header. Per RF…

Sunlithono · honoEPSS 0.24%via NVD
CVE-2026-71850Medium· 4.8
1mo ago

Hono is a Web application framework that provides support for any JavaScript runtime

Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from hono/jsx retains the result of a server side render and reuses it for later renders with comparator equal props, and…

Sunlithono · honoEPSS 0.16%via NVD
CVE-2026-69207Medium· 5.3
1mo ago

Hono is a Web application framework that provides support for any JavaScript runtime

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in CORS middleware, hono/cors, is vulnerable to a regular expression denial of service (ReDoS). During a preflight OPTIONS …

Sunlithono · honoEPSS 0.49%via NVD
CVE-2026-59897Medium· 4.8
2mo ago

Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication

Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication

Sunlithono · honoEPSS 0.18%via GHSA
CVE-2026-59895Medium· 6.1
2mo ago

Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility

Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility

Sunlithono · honoEPSS 0.33%via GHSA
CVE-2026-59896Medium· 6.5
2mo ago

hono/jsx does not isolate context per request, leading to cross-request data disclosure

hono/jsx does not isolate context per request, leading to cross-request data disclosure

Sunlithono · honoEPSS 0.30%via GHSA
CVE-2026-54287Medium· 5.3
3mo ago

hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice

hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice

Sunlithono · honoEPSS 0.31%via GHSA
CVE-2026-54286Medium· 5.9
3mo ago

hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)

hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)

Sunlithono · honoEPSS 0.43%via GHSA
CVE-2026-54290High· 7.1
3mo ago

hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard

hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard

Twilighthono · honoEPSS 0.33%via GHSA
CVE-2026-54289Medium· 4.8
3mo ago

hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest

hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest

Sunlithono · honoEPSS 0.18%via GHSA
CVE-2026-54288Medium· 6.5
3mo ago

hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`

hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`

Sunlithono · honoEPSS 0.15%via GHSA
hono vulnerabilities (CVEs) · VulnSea