hono
34 known vulnerabilities · 0 critical · 0 high
Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback)
Hono cache middleware ignores "Cache-Control: private" leading to Web Cache Deception
hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR
Hono allows bypass of CSRF Middleware by a request without Content-Type header.
Hono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)
Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses
Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie()
Hono: Non-breaking space prefix bypass in cookie name handling in getCookie()
Hono CSRF middleware can be bypassed using crafted Content-Type header
Hono added timing comparison hardening in basicAuth and bearerAuth
Hono vulnerable to Vary Header Injection leading to potential CORS Bypass
Hono IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing
Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })
Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE()
Hono missing validation of cookie name on write path in setCookie()
Hono vulnerable to Restricted Directory Traversal in serveStatic with deno
Hono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass
Hono: Middleware bypass via repeated slashes in serveStatic
Hono vulnerable to arbitrary file access via serveStatic vulnerability
Hono: Path traversal in toSSG() allows writing files outside the output directory
Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo
@hono/node-server: Middleware bypass via repeated slashes in serveStatic
Malicious code in @trpc-rate-limiter/hono (npm)
OpenClaw: Native prompt image auto-load did not honor tools.fs.workspaceOnly in sandboxed runs
@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware
The `size` option isn't honored after following a redirect in node-fetch
Malicious code in rce-poc-test-honor-dev (npm)
Malicious code in rce-poc-test-honor-mcp (npm)
Malicious code in @phonos/types (npm)