CVE-2026-47675
- EPSS 0.22%
- Veröffentlicht 28.05.2026 15:28:23
- Zuletzt bearbeitet 29.05.2026 16:56:59
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path options against characters that corrupt Set-Cookie header syntax (;, \r, \n), bu...
CVE-2026-47676
- EPSS 0.26%
- Veröffentlicht 28.05.2026 15:26:01
- Zuletzt bearbeitet 29.05.2026 16:55:56
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the incoming request path using the raw URL pathname, while route matching is performed against the perce...
CVE-2026-44459
- EPSS 0.22%
- Veröffentlicht 13.05.2026 15:02:23
- Zuletzt bearbeitet 13.05.2026 18:21:48
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validation of the JWT NumericDate claims exp, nbf, and iat in hono/utils/jwt allows tokens with non-spec-compliant claim values to silent...
CVE-2026-44458
- EPSS 0.2%
- Veröffentlicht 13.05.2026 15:01:37
- Zuletzt bearbeitet 13.05.2026 18:32:16
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer escapes style attribute object values for HTML but not for CSS. Untrusted input in a style object value or property name can ther...
CVE-2026-44457
- EPSS 0.2%
- Veröffentlicht 13.05.2026 14:58:52
- Zuletzt bearbeitet 13.05.2026 18:34:01
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware does not skip caching for responses that declare per-user variance via Vary: Authorization or Vary: Cookie. As a result, a respon...
CVE-2026-44456
- EPSS 0.22%
- Veröffentlicht 13.05.2026 14:58:08
- Zuletzt bearbeitet 13.05.2026 18:34:43
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does not reliably enforce maxSize for requests without a usable Content-Length (e.g. Transfer-Encoding: chunked). Oversized requests c...
CVE-2026-44455
- EPSS 0.14%
- Veröffentlicht 13.05.2026 14:57:05
- Zuletzt bearbeitet 13.05.2026 18:35:24
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, Improper handling of JSX element tag names in hono/jsx allowed unvalidated tag names to be directly inserted into the generated HTML output. When ...
CVE-2026-39410
- EPSS 0.28%
- Veröffentlicht 08.04.2026 14:44:40
- Zuletzt bearbeitet 24.07.2026 21:10:00
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy between browser cookie parsing and parse() handling allows cookie prefix protections to be bypassed. Cookie names that are treated a...
CVE-2026-39409
- EPSS 0.34%
- Veröffentlicht 08.04.2026 14:43:36
- Zuletzt bearbeitet 24.07.2026 21:10:00
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() does not canonicalize IPv4-mapped IPv6 client addresses (e.g. ::ffff:127.0.0.1) before applying IPv4 allow or deny rules. In envir...
CVE-2026-39408
- EPSS 0.53%
- Veröffentlicht 08.04.2026 14:42:25
- Zuletzt bearbeitet 24.07.2026 21:10:00
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows files to be written outside the configured output directory during static site generation. When using dyn...