VYPR
Low severity3.7OSV Advisory· Published Jul 15, 2026· Updated Jul 15, 2026

CVE-2026-56764

CVE-2026-56764

Description

Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual function. Attackers can exploit early termination of string equality checks to infer valid credentials through precise timing measurements.

Affected products

2
  • Honojs/HonoOSV2 versions
    v4.11.9, v4.11.8, v4.11.7, …+ 1 more
    • (no CPE)range: v4.11.9, v4.11.8, v4.11.7, …
    • (no CPE)range: <4.11.10

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.