Hono

Hono

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 12.09.2025 13:03:05
  • Zuletzt bearbeitet 17.09.2025 20:35:36

Hono is a Web application framework that provides support for any JavaScript runtime. In versions prior to 4.9.7, a flaw in the `bodyLimit` middleware could allow bypassing the configured request body size limit when conflicting HTTP headers were pre...

  • EPSS 0.04%
  • Veröffentlicht 04.09.2025 23:56:13
  • Zuletzt bearbeitet 17.09.2025 20:35:24

Hono is a Web application framework that provides support for any JavaScript runtime. Versions 4.8.0 through 4.9.5 contain a flaw in the getPath utility function which could allow path confusion and potential bypass of proxy-level ACLs (e.g. Nginx lo...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 15.10.2024 16:15:05
  • Zuletzt bearbeitet 17.09.2025 20:35:07

Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by a request without Content-Type header. Although the CSRF middleware verifies the Content-Type Header, Hono always considers a req...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 22.08.2024 15:15:16
  • Zuletzt bearbeitet 17.09.2025 20:34:47

Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypassed using crafted Content-Type header. MIME types are case insensitive, but isRequestedByFormElementRe only matches lower-case. As ...

Exploit
  • EPSS 0.98%
  • Veröffentlicht 23.04.2024 21:15:48
  • Zuletzt bearbeitet 17.09.2025 20:34:12

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.2.7, when using serveStatic with deno, it is possible to traverse the directory where `main.ts` is located. This can result in retrieval of unexp...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 14.12.2023 18:15:45
  • Zuletzt bearbeitet 21.11.2024 08:37:11

Hono is a web framework written in TypeScript. Prior to version 3.11.7, clients may override named path parameter values from previous requests if the application is using TrieRouter. So, there is a risk that a privileged user may use unintended para...