Low severity3.8GHSA Advisory· Published May 13, 2026· Updated May 13, 2026
CVE-2026-44459
CVE-2026-44459
Description
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validation of the JWT NumericDate claims exp, nbf, and iat in hono/utils/jwt allows tokens with non-spec-compliant claim values to silently bypass time-based checks. This issue is not exploitable by an anonymous attacker; it only manifests when a malformed claim value reaches verify() — typically when the application itself issues such tokens, or when the signing key is otherwise under attacker control. This vulnerability is fixed in 4.12.18.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
hononpm | < 4.12.18 | 4.12.18 |
Affected products
17- osv-coords16 versionspkg:apk/chainguard/kibana-9.1pkg:apk/chainguard/kibana-9.1-iamguardedpkg:apk/chainguard/kibana-9.3pkg:apk/chainguard/kibana-9.3-iamguardedpkg:apk/chainguard/kibana-9.4pkg:apk/chainguard/kibana-9.4-iamguardedpkg:apk/chainguard/langfuse-3-workerpkg:apk/chainguard/langfuse-fips-3-workerpkg:apk/chainguard/librechatpkg:apk/chainguard/opensearch-dashboards-2pkg:apk/chainguard/opensearch-dashboards-2-fipspkg:apk/chainguard/wazuh-dashboardpkg:apk/chainguard/wazuh-dashboard-fipspkg:apk/wolfi/langfuse-3-workerpkg:apk/wolfi/opensearch-dashboards-2pkg:npm/hono
< 9.1.10-r15+ 15 more
- (no CPE)range: < 9.1.10-r15
- (no CPE)range: < 9.1.10-r15
- (no CPE)range: < 9.3.4-r4
- (no CPE)range: < 9.3.4-r4
- (no CPE)range: < 9.4.2-r0
- (no CPE)range: < 9.4.2-r0
- (no CPE)range: < 3.176.0-r0
- (no CPE)range: < 3.176.0-r0
- (no CPE)range: < 0.8.4-r6
- (no CPE)range: < 2.19.5-r11
- (no CPE)range: < 2.19.5-r11
- (no CPE)range: < 4.14.4-r4
- (no CPE)range: < 4.14.4-r3
- (no CPE)range: < 3.176.0-r0
- (no CPE)range: < 2.19.5-r11
- (no CPE)range: < 4.12.18
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-hm8q-7f3q-5f36ghsaADVISORY
- github.com/honojs/hono/security/advisories/GHSA-hm8q-7f3q-5f36nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-44459ghsaADVISORY
News mentions
0No linked articles in our index yet.