hono has 18 CVEs on record. Disclosure cadence is accelerating: 13 in the last 90 days against 5 in the 90 before. The busiest recent month was June 2026 with 5. The median CVSS is 5.3 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-22 (3). Most affected products: hono (15), @hono/node-server (2), @hono/oauth-providers (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 13 prev 5
Weakness classes
Products
- hono 15
- @hono/node-server 2
- @hono/oauth-providers 1
Worst active — by depth score
CVE-2026-54290High· 7.1hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard39CVE-2026-84365Medium· 6.5Hono is a Web application framework that provides support for any JavaScript runtime36CVE-2026-59896Medium· 6.5hono/jsx does not isolate context per request, leading to cross-request data disclosure36CVE-2026-54288Medium· 6.5hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`36CVE-2026-59895Medium· 6.1Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility34
hono vulnerabilities
CVEs affecting hono, newest first. Open any entry for full detail, references, and exploit status.
18 CVEsRSS
CVE-2026-84365Medium· 6.5Hono is a Web application framework that provides support for any JavaScript runtime
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix released for CVE-2026-39408 does not cover every traversal sequence, and toSSG() can still write files outside the c…
CVE-2026-84364Medium· 5.3Hono is a Web application framework that provides support for any JavaScript runtime
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, when parseBody() expands dot-separated form field names into nested objects with dot-notation parsing enabled, it does not limit the n…
CVE-2026-84363Medium· 5.9Hono is a Web application framework that provides support for any JavaScript runtime
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, Hono's query helpers treat a question mark after a literal hash fragment as the start of a query string, so the application can read r…
CVE-2026-81888Medium· 5.4@hono/oauth-providers is Authentication middleware for Hono
@hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is absent on both sides, so the anti-CSRF check passes for a ca…
CVE-2026-71848Medium· 5.3Hono is a Web application framework that provides support for any JavaScript runtime
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the languageDetector middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language ta…
CVE-2026-71849Low· 3.7Hono is a Web application framework that provides support for any JavaScript runtime
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy Helper proxy() function in hono/proxy does not remove response headers named by the origin's Connection header. Per RF…
CVE-2026-71850Medium· 4.8Hono is a Web application framework that provides support for any JavaScript runtime
Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from hono/jsx retains the result of a server side render and reuses it for later renders with comparator equal props, and…
CVE-2026-69207Medium· 5.3Hono is a Web application framework that provides support for any JavaScript runtime
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in CORS middleware, hono/cors, is vulnerable to a regular expression denial of service (ReDoS). During a preflight OPTIONS …
GHSA-9mqv-5hh9-4cggMedium· 5.3Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
GHSA-frvp-7c67-39w9Medium· 5.9Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
CVE-2026-59897Medium· 4.8Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
CVE-2026-59895Medium· 6.1Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
CVE-2026-59896Medium· 6.5hono/jsx does not isolate context per request, leading to cross-request data disclosure
hono/jsx does not isolate context per request, leading to cross-request data disclosure
CVE-2026-54287Medium· 5.3hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice
hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice
CVE-2026-54286Medium· 5.9hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
CVE-2026-54290High· 7.1hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard
hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard
CVE-2026-54289Medium· 4.8hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest
hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest
CVE-2026-54288Medium· 6.5hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`