Hono

Hono

26 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 13.05.2026 15:02:23
  • Zuletzt bearbeitet 13.05.2026 18:21:48

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validation of the JWT NumericDate claims exp, nbf, and iat in hono/utils/jwt allows tokens with non-spec-compliant claim values to silent...

  • EPSS 0.04%
  • Veröffentlicht 13.05.2026 15:01:37
  • Zuletzt bearbeitet 13.05.2026 18:32:16

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer escapes style attribute object values for HTML but not for CSS. Untrusted input in a style object value or property name can ther...

  • EPSS 0.03%
  • Veröffentlicht 13.05.2026 14:58:52
  • Zuletzt bearbeitet 13.05.2026 18:34:01

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware does not skip caching for responses that declare per-user variance via Vary: Authorization or Vary: Cookie. As a result, a respon...

  • EPSS 0.03%
  • Veröffentlicht 13.05.2026 14:58:08
  • Zuletzt bearbeitet 13.05.2026 18:34:43

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does not reliably enforce maxSize for requests without a usable Content-Length (e.g. Transfer-Encoding: chunked). Oversized requests c...

  • EPSS 0.03%
  • Veröffentlicht 13.05.2026 14:57:05
  • Zuletzt bearbeitet 13.05.2026 18:35:24

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, Improper handling of JSX element tag names in hono/jsx allowed unvalidated tag names to be directly inserted into the generated HTML output. When ...

  • EPSS 0.03%
  • Veröffentlicht 08.04.2026 14:44:40
  • Zuletzt bearbeitet 21.04.2026 18:26:00

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy between browser cookie parsing and parse() handling allows cookie prefix protections to be bypassed. Cookie names that are treated a...

  • EPSS 0.01%
  • Veröffentlicht 08.04.2026 14:43:36
  • Zuletzt bearbeitet 21.04.2026 18:30:01

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() does not canonicalize IPv4-mapped IPv6 client addresses (e.g. ::ffff:127.0.0.1) before applying IPv4 allow or deny rules. In envir...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 08.04.2026 14:42:25
  • Zuletzt bearbeitet 21.04.2026 18:31:11

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows files to be written outside the configured output directory during static site generation. When using dyn...

  • EPSS 0.02%
  • Veröffentlicht 08.04.2026 14:41:20
  • Zuletzt bearbeitet 21.04.2026 18:36:36

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path. When...

  • EPSS 0.06%
  • Veröffentlicht 04.03.2026 22:09:45
  • Zuletzt bearbeitet 06.03.2026 18:03:12

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using streamSSE() in Streaming Helper, the event, id, and retry fields were not validated for carriage return (\r) or newline (\n) cha...