Hono
This hub aggregates every CVE we track for Hono, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
59
CVEs tracked
0
Critical
11
High
0
In CISA KEV
Severity distribution
MEDIUM40HIGH11LOW3
Monthly trend
1
0
0
0
0
0
0
0
0
0
0
2
2
0
0
6
2
4
6
10
8
5
4
4
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Hono.
- CVE-2026-93981hono/jsx before 4.13.7 Cross-Site Scripting via Unescaped Strings4.7
- CVE-2026-84365Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory6.5
- CVE-2026-84364Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion5.3
- CVE-2026-84363Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials5.9
- CVE-2026-69207Hono: ReDoS in CORS middleware via Access-Control-Request-Headers5.3
- CVE-2026-71850Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure4.8
- CVE-2026-71849Hono: Proxy Helper does not remove response headers listed in the `Connection` header3.7
- CVE-2026-71848Hono: Algorithmic Complexity DoS in Language Middleware5.3
- CVE-2026-56764Hono - Timing Attack in basicAuth and bearerAuth Middleware3.7
- CVE-2026-56763Hono - Prototype Pollution via __proto__ Key in parseBody with dot Option4.8
- CVE-2026-59895Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility6.1
- CVE-2026-59896hono/jsx does not isolate context per request, leading to cross-request data disclosure6.5
- CVE-2026-59897Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication4.8
- CVE-2025-71381Hono - Vary Header Injection in CORS Middleware6.5
- CVE-2026-56761hono - HTML Injection via Improper JSX Attribute Name Handling in SSR4.3
Product normalization is registry-driven with AI assist and human review. How it works