honojs
OSS Librariesoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting honojs.
- CVE-2026-73565@hono/node-server: Unauthenticated memory-leak DoS via aborted WebSocket handshake5.3
- CVE-2026-69207Hono: ReDoS in CORS middleware via Access-Control-Request-Headers5.3
- CVE-2026-71850Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure4.8
- CVE-2026-71849Hono: Proxy Helper does not remove response headers listed in the `Connection` header3.7
- CVE-2026-71848Hono: Algorithmic Complexity DoS in Language Middleware5.3
- CVE-2026-59895Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility6.1
- CVE-2026-59896hono/jsx does not isolate context per request, leading to cross-request data disclosure6.5
- CVE-2026-59897Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication4.8
- CVE-2026-54288Hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`6.5
- CVE-2026-54289Hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest4.8
- CVE-2026-54290Hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard7.1
- CVE-2026-54286Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)5.9
- CVE-2026-54287Hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice5.3
- CVE-2026-47673Hono: JWT middleware accepts any Authorization scheme, not only Bearer4.8
- CVE-2026-47674Hono: IP Restriction bypasses static deny rules for non-canonical IPv65.3