Vulnerabilities

Last updated 48 minutes ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
hono Hono missing validation of cookie name on write path in setCookie() Medium Risk 5.3 5 months ago 3 days ago
@hono/oauth-providers @hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking Medium Risk 5.4 27 days ago 13 days ago
hono Hono: Proxy Helper does not remove response headers listed in the `Connection` header Low Risk 3.7 1 month ago 18 days ago
hono Hono: ReDoS in CORS middleware via Access-Control-Request-Headers Medium Risk 5.3 1 month ago 18 days ago
hono Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure Medium Risk 4.8 1 month ago 18 days ago
hono Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility Medium Risk 6.1 2 months ago 18 days ago
hono Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 Medium Risk 5.3 3 months ago 18 days ago
hono Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths Medium Risk 5.3 3 months ago 18 days ago
hono Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage Medium Risk 5.3 4 months ago 18 days ago
hono Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify() Low Risk 3.8 4 months ago 18 days ago
@clerk/hono Clerk has an authorization bypass when combining organization, billing, or reverification checks High Risk 8.1 5 months ago 18 days ago
hono Hono: Path traversal in toSSG() allows writing files outside the output directory Medium Risk 6.0 5 months ago 18 days ago
hono Hono: Non-breaking space prefix bypass in cookie name handling in getCookie() Medium Risk 4.8 5 months ago 18 days ago
@hono/node-server @hono/node-server: Middleware bypass via repeated slashes in serveStatic Medium Risk 5.3 5 months ago 18 days ago
hono Hono IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing Medium Risk 4.8 8 months ago 18 days ago
hono Hono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter) Medium Risk 5.3 8 months ago 18 days ago
hono Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback) High Risk 8.2 8 months ago 18 days ago
hono Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection Medium Risk 4.3 3 months ago 18 days ago
hono Hono CSRF middleware can be bypassed using crafted Content-Type header Medium Risk 5.0 2 years ago 18 days ago
hono Hono: Algorithmic Complexity DoS in Language Middleware Medium Risk 5.3 1 month ago 18 days ago
hono Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication Medium Risk 4.8 2 months ago 18 days ago
@hono/node-server Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) Medium Risk 5.9 2 months ago 18 days ago
hono hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) Medium Risk 5.9 3 months ago 18 days ago
hono hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length` Medium Risk 6.5 3 months ago 18 days ago
hono hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest Medium Risk 4.8 3 months ago 18 days ago
hono Hono: JWT middleware accepts any Authorization scheme, not only Bearer Medium Risk 4.8 3 months ago 18 days ago
hono hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice Medium Risk 5.3 3 months ago 18 days ago
hono hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard High Risk 7.1 3 months ago 18 days ago
hono Hono has CSS Declaration Injection via Style Object Values in JSX SSR Medium Risk 4.3 4 months ago 18 days ago
hono Hono: bodyLimit() can be bypassed for chunked / unknown-length requests Medium Risk 6.5 4 months ago 18 days ago
hono hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection Medium Risk 4.7 4 months ago 18 days ago
hono Hono: Middleware bypass via repeated slashes in serveStatic Medium Risk 5.3 5 months ago 18 days ago
hono Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses Medium Risk 5.3 5 months ago 18 days ago
hono hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR Medium Risk 4.3 5 months ago 18 days ago
hono Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true }) Medium Risk 4.8 6 months ago 18 days ago
@hono/node-server @hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware High Risk 7.5 6 months ago 18 days ago
hono Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE() Medium Risk 6.5 6 months ago 18 days ago
hono Hono vulnerable to arbitrary file access via serveStatic vulnerability High Risk 7.5 6 months ago 18 days ago
hono Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie() Medium Risk 5.4 6 months ago 18 days ago
hono Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo High Risk 8.2 7 months ago 18 days ago
hono Hono added timing comparison hardening in basicAuth and bearerAuth Low Risk 3.7 7 months ago 18 days ago
hono Hono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass High Risk 8.2 8 months ago 18 days ago
hono Hono cache middleware ignores "Cache-Control: private" leading to Web Cache Deception Medium Risk 5.3 8 months ago 18 days ago
hono Hono vulnerable to XSS through ErrorBoundary component Medium Risk 4.7 8 months ago 18 days ago
hono Hono Improper Authorization vulnerability High Risk 8.1 11 months ago 18 days ago
hono Hono has Body Limit Middleware Bypass Medium Risk 5.3 1 year ago 18 days ago
hono Hono allows bypass of CSRF Middleware by a request without Content-Type header. Medium Risk 5.9 1 year ago 18 days ago
hono hono/jsx does not isolate context per request, leading to cross-request data disclosure Medium Risk 6.5 2 months ago 18 days ago
hono Hono vulnerable to Restricted Directory Traversal in serveStatic with deno Medium Risk 5.3 2 years ago 18 days ago
@hono/node-server @hono/node-server has Denial of Service risk when receiving Host header that cannot be parsed High Risk 7.5 2 years ago 18 days ago