Honojs
Products
28- Hono47 CVEsnpm
- 43 CVEs
- 18 CVEs
- 8 CVEs
- 5 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 0 CVEs
- 0 CVEs
- 0 CVEs
- 0 CVEs
- 0 CVEs
- 0 CVEs
Recent CVEs
109| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-9144 | Cri | 0.64 | 9.8 | 0.01 | Jan 13, 2021 | There is a heap overflow vulnerability in some Huawei smartphone, attackers can exploit this vulnerability to cause heap overflows due to improper restriction of operations within the bounds of a memory buffer. | ||
| CVE-2023-51434 | Cri | 0.60 | 9.3 | 0.00 | Dec 29, 2023 | Some Honor products are affected by buffer overflow vulnerability, successful exploitation could cause code execution. | ||
| CVE-2025-46014 | Hig | 0.57 | 8.8 | 0.00 | Jun 30, 2025 | Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistant with default or overly permissive security attributes, leading to a privilege escalation. | ||
| CVE-2019-5218 | Hig | 0.57 | 8.8 | 0.00 | Nov 29, 2019 | There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently authenticate the device try to connect to it in certain scenario. Successful exploit could allow the attacker to spoof then connect to the band. | ||
| CVE-2025-2188 | Hig | 0.53 | 8.1 | 0.00 | Apr 17, 2025 | There is a whitelist mechanism bypass in GameCenter ,successful exploitation of this vulnerability may affect service confidentiality and integrity. | ||
| CVE-2025-1532 | Hig | 0.53 | 8.1 | 0.00 | Apr 17, 2025 | Phoneservice module is affected by code injection vulnerability, successful exploitation of this vulnerability may affect service confidentiality and integrity. | ||
| CVE-2026-31368 | Hig | 0.51 | 7.8 | 0.00 | Apr 21, 2026 | AiAssistant is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability. | ||
| CVE-2023-23436 | Hig | 0.47 | 7.3 | 0.00 | Dec 29, 2023 | Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file | ||
| CVE-2023-23432 | Hig | 0.47 | 7.3 | 0.00 | Dec 29, 2023 | Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file. | ||
| CVE-2023-23431 | Hig | 0.47 | 7.3 | 0.00 | Dec 29, 2023 | Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file. | ||
| CVE-2026-27700 | Hig | 0.46 | 8.2 | 0.00 | Feb 25, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. In versions 4.12.0 and 4.12.1, when using the AWS Lambda adapter (`hono/aws-lambda`) behind an Application Load Balancer (ALB), the `getConnInfo()` function incorrectly selected the first value… | ||
| CVE-2026-22818 | Hig | 0.46 | 8.2 | 0.00 | Jan 13, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the algorithm specified in the JWT header to influence signature verification when the selected JWK did… | ||
| CVE-2026-22817 | Hig | 0.46 | 8.2 | 0.00 | Jan 13, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the JWT header’s alg value to influence signature verification when the selected JWK did not… | ||
| CVE-2025-62610 | Hig | 0.46 | 8.1 | 0.00 | Oct 22, 2025 | Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4.10.2, Hono’s JWT Auth Middleware does not provide a built-in aud (Audience) verification option, which can cause confused-deputy / token-mix-up issues: an… | ||
| CVE-2023-51435 | Hig | 0.46 | 7.1 | 0.00 | Dec 29, 2023 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak. | ||
| CVE-2023-51431 | Hig | 0.46 | 7.0 | 0.00 | Dec 29, 2023 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. | ||
| CVE-2023-23426 | Med | 0.43 | 6.6 | 0.00 | Dec 29, 2023 | Some Honor products are affected by file writing vulnerability, successful exploitation could cause information disclosure. | ||
| CVE-2026-39408 | Hig | 0.42 | 7.5 | 0.01 | Apr 8, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows files to be written outside the configured output directory during static site generation. When using dynamic route parameters via… | ||
| CVE-2026-29087 | Hig | 0.42 | 7.5 | 0.00 | Mar 6, 2026 | @hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware protections (e.g. protecting /admin/*), inconsistent URL decoding can allow protected static… | ||
| CVE-2026-29045 | Hig | 0.42 | 7.5 | 0.00 | Mar 4, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protections (e.g. app.use('/admin/*', ...)), inconsistent URL decoding allowed protected static resources to… |
- risk 0.64cvss 9.8epss 0.01
There is a heap overflow vulnerability in some Huawei smartphone, attackers can exploit this vulnerability to cause heap overflows due to improper restriction of operations within the bounds of a memory buffer.
- risk 0.60cvss 9.3epss 0.00
Some Honor products are affected by buffer overflow vulnerability, successful exploitation could cause code execution.
- risk 0.57cvss 8.8epss 0.00
Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistant with default or overly permissive security attributes, leading to a privilege escalation.
- risk 0.57cvss 8.8epss 0.00
There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently authenticate the device try to connect to it in certain scenario. Successful exploit could allow the attacker to spoof then connect to the band.
- risk 0.53cvss 8.1epss 0.00
There is a whitelist mechanism bypass in GameCenter ,successful exploitation of this vulnerability may affect service confidentiality and integrity.
- risk 0.53cvss 8.1epss 0.00
Phoneservice module is affected by code injection vulnerability, successful exploitation of this vulnerability may affect service confidentiality and integrity.
- risk 0.51cvss 7.8epss 0.00
AiAssistant is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability.
- risk 0.47cvss 7.3epss 0.00
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file
- risk 0.47cvss 7.3epss 0.00
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.
- risk 0.47cvss 7.3epss 0.00
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.
- risk 0.46cvss 8.2epss 0.00
Hono is a Web application framework that provides support for any JavaScript runtime. In versions 4.12.0 and 4.12.1, when using the AWS Lambda adapter (`hono/aws-lambda`) behind an Application Load Balancer (ALB), the `getConnInfo()` function incorrectly selected the first value…
- risk 0.46cvss 8.2epss 0.00
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the algorithm specified in the JWT header to influence signature verification when the selected JWK did…
- risk 0.46cvss 8.2epss 0.00
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the JWT header’s alg value to influence signature verification when the selected JWK did not…
- risk 0.46cvss 8.1epss 0.00
Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4.10.2, Hono’s JWT Auth Middleware does not provide a built-in aud (Audience) verification option, which can cause confused-deputy / token-mix-up issues: an…
- risk 0.46cvss 7.1epss 0.00
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.
- risk 0.46cvss 7.0epss 0.00
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
- risk 0.43cvss 6.6epss 0.00
Some Honor products are affected by file writing vulnerability, successful exploitation could cause information disclosure.
- risk 0.42cvss 7.5epss 0.01
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows files to be written outside the configured output directory during static site generation. When using dynamic route parameters via…
- risk 0.42cvss 7.5epss 0.00
@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware protections (e.g. protecting /admin/*), inconsistent URL decoding can allow protected static…
- risk 0.42cvss 7.5epss 0.00
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protections (e.g. app.use('/admin/*', ...)), inconsistent URL decoding allowed protected static resources to…