Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hono MEDIUM 6.5
CVE-2026-59896

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context va…

Fix: 4.12.27+
Fix from $1,600 2026-07-08
Hono MEDIUM 6.1
CVE-2026-59895

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class name…

Fix: 4.12.27+
Fix from $1,600 2026-07-08
Hono MEDIUM 5.3
CVE-2026-59897

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can d…

Fix: 4.12.27+
Fix from $1,600 2026-07-08
Hono MEDIUM 6.5
CVE-2026-47673

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify tha…

Fix: 4.12.21+
Fix from $1,600 2026-05-28
Hono MEDIUM 5.3
CVE-2026-47674

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restri…

Fix: 4.12.21+
Fix from $1,600 2026-05-28
Hono MEDIUM 5.3
CVE-2026-47675

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie valid…

Fix: 4.12.21+
Fix from $1,600 2026-05-28
Hono MEDIUM 5.3
CVE-2026-47676

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the …

Fix: 4.12.21+
Fix from $1,600 2026-05-28
Hono MEDIUM 6.5
CVE-2026-44456

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does not reliably enforce maxSize…

Fix: 4.12.16+
Fix from $1,600 2026-05-13
Hono MEDIUM 6.1
CVE-2026-44455

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, Improper handling of JSX element tag names in…

Fix: 4.12.16+
Fix from $1,600 2026-05-13
Hono MEDIUM 5.3
CVE-2026-44457

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware does not skip caching for re…

Fix: 4.12.18+
Fix from $1,600 2026-05-13
Hono HIGH 7.5
CVE-2026-39408

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows file…

Fix: after 4.12.11
Fix from $1,950 2026-04-08
Node Server MEDIUM 5.3
CVE-2026-39406

@hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in serveStatic allows protected sta…

Fix: after 1.19.12
Fix from $1,600 2026-04-08
Hono MEDIUM 5.3
CVE-2026-39407

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path handling inconsistency in serveStatic …

Fix: after 4.12.11
Fix from $1,600 2026-04-08
Hono MEDIUM 5.3
CVE-2026-39409

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() does not canonicalize IPv4-ma…

Fix: after 4.12.11
Fix from $1,600 2026-04-08
Node Server HIGH 7.5
CVE-2026-29087

@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving togeth…

Fix: 1.19.10+
Fix from $1,950 2026-03-06
Hono CRITICAL 9.8
CVE-2026-29045

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with r…

Fix: 4.12.4+
Fix from $2,300 2026-03-04
Hono MEDIUM 6.5
CVE-2026-29085

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using streamSSE() in Streaming He…

Fix: 4.12.4+
Fix from $1,600 2026-03-04
Hono MEDIUM 5.4
CVE-2026-29086

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, the setCookie() utility did not valida…

Fix: 4.12.4+
Fix from $1,600 2026-03-04
Hono HIGH 7.5
CVE-2026-27700

Hono is a Web application framework that provides support for any JavaScript runtime. In versions 4.12.0 and 4.12.1, when using the AWS Lambda adapte…

Fix: 4.12.2+
Fix from $1,950 2026-02-25
Hono MEDIUM 5.3
CVE-2026-24473

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Serve static Middleware for the Cloudf…

Fix: 4.11.7+
Fix from $1,600 2026-01-27
Hono MEDIUM 5.3
CVE-2026-24472

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Cache Middleware contains an informati…

Fix: 4.11.7+
Fix from $1,600 2026-01-27
Hono MEDIUM 6.5
CVE-2026-24398

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, IP Restriction Middleware in Hono is v…

Fix: 4.11.7+
Fix from $1,600 2026-01-27
Hono MEDIUM 6.5
CVE-2026-22817

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verific…

Fix: 4.11.4+
Fix from $1,600 2026-01-13
Hono MEDIUM 6.5
CVE-2026-22818

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verific…

Fix: 4.11.4+
Fix from $1,600 2026-01-13
Hono HIGH 8.1
CVE-2025-62610

Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4.10.2, Hono’s JWT Auth Middle…

Fix: 4.10.2+
Fix from $1,950 2025-10-22
Hono MEDIUM 5.3
CVE-2025-59139

Hono is a Web application framework that provides support for any JavaScript runtime. In versions prior to 4.9.7, a flaw in the `bodyLimit` middlewar…

Fix: 4.9.7+
Fix from $1,600 2025-09-12
Hono HIGH 7.5
CVE-2025-58362

Hono is a Web application framework that provides support for any JavaScript runtime. Versions 4.8.0 through 4.9.5 contain a flaw in the getPath util…

Fix: 4.9.6+
Fix from $1,950 2025-09-05
Hono MEDIUM 5.9
CVE-2024-48913

Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by a request without Content-Ty…

Fix: 4.6.5+
Fix from $1,600 2024-10-15
Hono MEDIUM 5.0
CVE-2024-43787

Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypassed using crafted Content-Type…

Fix: 4.5.8+
Fix from $1,600 2024-08-22
Hono MEDIUM 5.3
CVE-2024-32869

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.2.7, when using serveStatic with deno, it is…

Fix: 4.2.7+
Fix from $1,600 2024-04-23