Security Advisories for hono in npm
Moderate
21 days ago
Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
npm
hono
Low
21 days ago
Hono: Proxy Helper does not remove response headers listed in the `Connection` header
npm
hono
Moderate
about 1 month ago
hono/jsx does not isolate context per request, leading to cross-request data disclosure
npm
hono
Moderate
about 1 month ago
Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
npm
hono
Moderate
2 months ago
hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
npm
hono
Moderate
2 months ago
hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest
npm
hono
High
2 months ago
hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard
npm
hono
Moderate
2 months ago
hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
npm
hono
Moderate
3 months ago
Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths
npm
hono
Moderate
3 months ago
Hono: IP Restriction bypasses static deny rules for non-canonical IPv6
npm
hono
Moderate
3 months ago
Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection
npm
hono
Moderate
3 months ago
Hono: JWT middleware accepts any Authorization scheme, not only Bearer
npm
hono
Moderate
4 months ago
Hono has CSS Declaration Injection via Style Object Values in JSX SSR
npm
hono
Low
4 months ago
Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()
npm
hono
Moderate
4 months ago
Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage
npm
hono
Moderate
4 months ago
Hono: bodyLimit() can be bypassed for chunked / unknown-length requests
npm
hono
Moderate
4 months ago
hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR
npm
hono
Moderate
5 months ago
Hono: Non-breaking space prefix bypass in cookie name handling in getCookie()
npm
hono
Moderate
5 months ago
Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses
npm
hono
Moderate
5 months ago
Hono: Path traversal in toSSG() allows writing files outside the output directory
npm
hono
Moderate
6 months ago
Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })
npm
hono
Moderate
6 months ago
Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie()
npm
hono
Moderate
6 months ago
Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE()
npm
hono
High
6 months ago
Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo
npm
hono
Moderate
7 months ago
Hono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)
npm
hono
Moderate
7 months ago
Hono cache middleware ignores "Cache-Control: private" leading to Web Cache Deception
npm
hono
Moderate
7 months ago
Hono IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing
npm
hono
High
8 months ago
Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback)
npm
hono
Moderate
10 months ago
Hono vulnerable to Vary Header Injection leading to potential CORS Bypass
npm
hono
Moderate
almost 2 years ago
Hono allows bypass of CSRF Middleware by a request without Content-Type header.
npm
hono
Low
about 2 years ago
Hono CSRF middleware can be bypassed using crafted Content-Type header
npm
hono
Moderate
over 2 years ago
Hono vulnerable to Restricted Directory Traversal in serveStatic with deno
npm
hono