Medium severity4.7GHSA Advisory· Published May 13, 2026· Updated May 13, 2026
CVE-2026-44455
CVE-2026-44455
Description
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, Improper handling of JSX element tag names in hono/jsx allowed unvalidated tag names to be directly inserted into the generated HTML output. When untrusted input is used as a tag name via the programmatic jsx() or createElement() APIs during server-side rendering, specially crafted values may break out of the intended element context and inject unintended HTML. This vulnerability is fixed in 4.12.16.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
hononpm | < 4.12.16 | 4.12.16 |
Affected products
13- osv-coords11 versionspkg:apk/chainguard/hono-service-authpkg:apk/chainguard/kibana-9.1pkg:apk/chainguard/kibana-9.1-iamguardedpkg:apk/chainguard/kibana-9.3pkg:apk/chainguard/kibana-9.3-iamguardedpkg:apk/chainguard/kibana-9.4pkg:apk/chainguard/kibana-9.4-iamguardedpkg:apk/chainguard/librechatpkg:apk/chainguard/wazuh-dashboardpkg:apk/chainguard/wazuh-dashboard-fipspkg:npm/hono
< 0+ 10 more
- (no CPE)range: < 0
- (no CPE)range: < 9.1.10-r15
- (no CPE)range: < 9.1.10-r15
- (no CPE)range: < 9.3.4-r4
- (no CPE)range: < 9.3.4-r4
- (no CPE)range: < 9.4.2-r0
- (no CPE)range: < 9.4.2-r0
- (no CPE)range: < 0.8.4-r6
- (no CPE)range: < 4.14.4-r4
- (no CPE)range: < 4.14.4-r3
- (no CPE)range: < 4.12.16
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-69xw-7hcm-h432ghsaADVISORY
- github.com/honojs/hono/security/advisories/GHSA-69xw-7hcm-h432nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-44455ghsaADVISORY
News mentions
0No linked articles in our index yet.