CVE-2025-59139
- EPSS 0.05%
- Veröffentlicht 12.09.2025 13:03:05
- Zuletzt bearbeitet 17.09.2025 20:35:36
Hono is a Web application framework that provides support for any JavaScript runtime. In versions prior to 4.9.7, a flaw in the `bodyLimit` middleware could allow bypassing the configured request body size limit when conflicting HTTP headers were pre...
CVE-2025-58362
- EPSS 0.04%
- Veröffentlicht 04.09.2025 23:56:13
- Zuletzt bearbeitet 17.09.2025 20:35:24
Hono is a Web application framework that provides support for any JavaScript runtime. Versions 4.8.0 through 4.9.5 contain a flaw in the getPath utility function which could allow path confusion and potential bypass of proxy-level ACLs (e.g. Nginx lo...
CVE-2024-48913
- EPSS 0.05%
- Veröffentlicht 15.10.2024 16:15:05
- Zuletzt bearbeitet 17.09.2025 20:35:07
Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by a request without Content-Type header. Although the CSRF middleware verifies the Content-Type Header, Hono always considers a req...
- EPSS 0.03%
- Veröffentlicht 22.08.2024 15:15:16
- Zuletzt bearbeitet 17.09.2025 20:34:47
Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypassed using crafted Content-Type header. MIME types are case insensitive, but isRequestedByFormElementRe only matches lower-case. As ...
CVE-2024-32869
- EPSS 0.98%
- Veröffentlicht 23.04.2024 21:15:48
- Zuletzt bearbeitet 17.09.2025 20:34:12
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.2.7, when using serveStatic with deno, it is possible to traverse the directory where `main.ts` is located. This can result in retrieval of unexp...
CVE-2023-50710
- EPSS 0.36%
- Veröffentlicht 14.12.2023 18:15:45
- Zuletzt bearbeitet 21.11.2024 08:37:11
Hono is a web framework written in TypeScript. Prior to version 3.11.7, clients may override named path parameter values from previous requests if the application is using TrieRouter. So, there is a risk that a privileged user may use unintended para...