hono vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-71850Mediumhono: Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosureCVE-2026-71849Lowhono: Hono: Proxy Helper does not remove response headers listed in the `Connection` headerCVE-2026-71848Mediumhono: Hono: Algorithmic Complexity DoS in Language MiddlewareCVE-2026-69207Mediumhono: Hono: ReDoS in CORS middleware via Access-Control-Request-HeadersCVE-2026-59896Mediumhono: hono/jsx does not isolate context per request, leading to cross-request data disclosureCVE-2026-59895Mediumhono: Hono: Server-Side XSS via JSX Escaping Bypass in cx() UtilityCVE-2026-59897Mediumhono: Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplicationCVE-2026-54288Mediumhono: hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`CVE-2026-54289Mediumhono: hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the restCVE-2026-54290Highhono: hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcardCVE-2026-54286Mediumhono: hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)CVE-2026-54287Mediumhono: hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and LatticeCVE-2026-47676Mediumhono: Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded pathsCVE-2026-47674Mediumhono: Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 CVE-2026-47675Mediumhono: Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injectionCVE-2026-47673Mediumhono: Hono: JWT middleware accepts any Authorization scheme, not only BearerCVE-2026-44458Mediumhono: Hono has CSS Declaration Injection via Style Object Values in JSX SSRCVE-2026-44459Lowhono: Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()CVE-2026-44457Mediumhono: Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakageCVE-2026-44456Mediumhono: Hono: bodyLimit() can be bypassed for chunked / unknown-length requestsCVE-2026-44455Mediumhono: hono/jsx has Unvalidated JSX Tag Names that May Allow HTML InjectionCVE-2026-56761Mediumhono: hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSRCVE-2026-39410Mediumhono: Hono: Non-breaking space prefix bypass in cookie name handling in getCookie()CVE-2026-39409Mediumhono: Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addressesGHSA-26PP-8WGV-HJVMMediumhono: Hono missing validation of cookie name on write path in setCookie()

Stop the waste.
Protect your environment with Kodem.