Vulnerabilities
Last updated 48 minutes ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
Hono missing validation of cookie name on write path in setCookie() | Medium Risk 5.3 | 5 months ago | 3 days ago |
|
|
@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking | Medium Risk 5.4 | 27 days ago | 13 days ago |
|
|
Hono: Proxy Helper does not remove response headers listed in the `Connection` header | Low Risk 3.7 | 1 month ago | 18 days ago |
|
|
Hono: ReDoS in CORS middleware via Access-Control-Request-Headers | Medium Risk 5.3 | 1 month ago | 18 days ago |
|
|
Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure | Medium Risk 4.8 | 1 month ago | 18 days ago |
|
|
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility | Medium Risk 6.1 | 2 months ago | 18 days ago |
|
|
Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 | Medium Risk 5.3 | 3 months ago | 18 days ago |
|
|
Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths | Medium Risk 5.3 | 3 months ago | 18 days ago |
|
|
Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage | Medium Risk 5.3 | 4 months ago | 18 days ago |
|
|
Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify() | Low Risk 3.8 | 4 months ago | 18 days ago |
|
|
Clerk has an authorization bypass when combining organization, billing, or reverification checks | High Risk 8.1 | 5 months ago | 18 days ago |
|
|
Hono: Path traversal in toSSG() allows writing files outside the output directory | Medium Risk 6.0 | 5 months ago | 18 days ago |
|
|
Hono: Non-breaking space prefix bypass in cookie name handling in getCookie() | Medium Risk 4.8 | 5 months ago | 18 days ago |
|
|
@hono/node-server: Middleware bypass via repeated slashes in serveStatic | Medium Risk 5.3 | 5 months ago | 18 days ago |
|
|
Hono IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing | Medium Risk 4.8 | 8 months ago | 18 days ago |
|
|
Hono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter) | Medium Risk 5.3 | 8 months ago | 18 days ago |
|
|
Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback) | High Risk 8.2 | 8 months ago | 18 days ago |
|
|
Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection | Medium Risk 4.3 | 3 months ago | 18 days ago |
|
|
Hono CSRF middleware can be bypassed using crafted Content-Type header | Medium Risk 5.0 | 2 years ago | 18 days ago |
|
|
Hono: Algorithmic Complexity DoS in Language Middleware | Medium Risk 5.3 | 1 month ago | 18 days ago |
|
|
Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication | Medium Risk 4.8 | 2 months ago | 18 days ago |
|
|
Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) | Medium Risk 5.9 | 2 months ago | 18 days ago |
|
|
hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) | Medium Risk 5.9 | 3 months ago | 18 days ago |
|
|
hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length` | Medium Risk 6.5 | 3 months ago | 18 days ago |
|
|
hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest | Medium Risk 4.8 | 3 months ago | 18 days ago |
|
|
Hono: JWT middleware accepts any Authorization scheme, not only Bearer | Medium Risk 4.8 | 3 months ago | 18 days ago |
|
|
hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice | Medium Risk 5.3 | 3 months ago | 18 days ago |
|
|
hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard | High Risk 7.1 | 3 months ago | 18 days ago |
|
|
Hono has CSS Declaration Injection via Style Object Values in JSX SSR | Medium Risk 4.3 | 4 months ago | 18 days ago |
|
|
Hono: bodyLimit() can be bypassed for chunked / unknown-length requests | Medium Risk 6.5 | 4 months ago | 18 days ago |
|
|
hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection | Medium Risk 4.7 | 4 months ago | 18 days ago |
|
|
Hono: Middleware bypass via repeated slashes in serveStatic | Medium Risk 5.3 | 5 months ago | 18 days ago |
|
|
Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses | Medium Risk 5.3 | 5 months ago | 18 days ago |
|
|
hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR | Medium Risk 4.3 | 5 months ago | 18 days ago |
|
|
Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true }) | Medium Risk 4.8 | 6 months ago | 18 days ago |
|
|
@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware | High Risk 7.5 | 6 months ago | 18 days ago |
|
|
Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE() | Medium Risk 6.5 | 6 months ago | 18 days ago |
|
|
Hono vulnerable to arbitrary file access via serveStatic vulnerability | High Risk 7.5 | 6 months ago | 18 days ago |
|
|
Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie() | Medium Risk 5.4 | 6 months ago | 18 days ago |
|
|
Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo | High Risk 8.2 | 7 months ago | 18 days ago |
|
|
Hono added timing comparison hardening in basicAuth and bearerAuth | Low Risk 3.7 | 7 months ago | 18 days ago |
|
|
Hono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass | High Risk 8.2 | 8 months ago | 18 days ago |
|
|
Hono cache middleware ignores "Cache-Control: private" leading to Web Cache Deception | Medium Risk 5.3 | 8 months ago | 18 days ago |
|
|
Hono vulnerable to XSS through ErrorBoundary component | Medium Risk 4.7 | 8 months ago | 18 days ago |
|
|
Hono Improper Authorization vulnerability | High Risk 8.1 | 11 months ago | 18 days ago |
|
|
Hono has Body Limit Middleware Bypass | Medium Risk 5.3 | 1 year ago | 18 days ago |
|
|
Hono allows bypass of CSRF Middleware by a request without Content-Type header. | Medium Risk 5.9 | 1 year ago | 18 days ago |
|
|
hono/jsx does not isolate context per request, leading to cross-request data disclosure | Medium Risk 6.5 | 2 months ago | 18 days ago |
|
|
Hono vulnerable to Restricted Directory Traversal in serveStatic with deno | Medium Risk 5.3 | 2 years ago | 18 days ago |
|
|
@hono/node-server has Denial of Service risk when receiving Host header that cannot be parsed | High Risk 7.5 | 2 years ago | 18 days ago |
Page 1