Vendor CVEs
Honojs
All CVEs
109 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-9144 | Cri | 0.64 | 9.8 | 0.01 | Jan 13, 2021 | There is a heap overflow vulnerability in some Huawei smartphone, attackers can exploit this vulnerability to cause heap overflows due to improper restriction of operations within the bounds of a memory buffer. | ||
| CVE-2023-51434 | Cri | 0.60 | 9.3 | 0.00 | Dec 29, 2023 | Some Honor products are affected by buffer overflow vulnerability, successful exploitation could cause code execution. | ||
| CVE-2025-46014 | Hig | 0.57 | 8.8 | 0.00 | Jun 30, 2025 | Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistant with default or overly permissive security attributes, leading to a privilege escalation. | ||
| CVE-2019-5218 | Hig | 0.57 | 8.8 | 0.00 | Nov 29, 2019 | There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently authenticate the device try to connect to it in certain scenario. Successful exploit could allow the attacker to spoof then connect to the band. | ||
| CVE-2025-2188 | Hig | 0.53 | 8.1 | 0.00 | Apr 17, 2025 | There is a whitelist mechanism bypass in GameCenter ,successful exploitation of this vulnerability may affect service confidentiality and integrity. | ||
| CVE-2025-1532 | Hig | 0.53 | 8.1 | 0.00 | Apr 17, 2025 | Phoneservice module is affected by code injection vulnerability, successful exploitation of this vulnerability may affect service confidentiality and integrity. | ||
| CVE-2026-31368 | Hig | 0.51 | 7.8 | 0.00 | Apr 21, 2026 | AiAssistant is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability. | ||
| CVE-2023-23436 | Hig | 0.47 | 7.3 | 0.00 | Dec 29, 2023 | Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file | ||
| CVE-2023-23432 | Hig | 0.47 | 7.3 | 0.00 | Dec 29, 2023 | Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file. | ||
| CVE-2023-23431 | Hig | 0.47 | 7.3 | 0.00 | Dec 29, 2023 | Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file. | ||
| CVE-2026-27700 | Hig | 0.46 | 8.2 | 0.00 | Feb 25, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. In versions 4.12.0 and 4.12.1, when using the AWS Lambda adapter (`hono/aws-lambda`) behind an Application Load Balancer (ALB), the `getConnInfo()` function incorrectly selected the first value… | ||
| CVE-2026-22818 | Hig | 0.46 | 8.2 | 0.00 | Jan 13, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the algorithm specified in the JWT header to influence signature verification when the selected JWK did… | ||
| CVE-2026-22817 | Hig | 0.46 | 8.2 | 0.00 | Jan 13, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the JWT header’s alg value to influence signature verification when the selected JWK did not… | ||
| CVE-2025-62610 | Hig | 0.46 | 8.1 | 0.00 | Oct 22, 2025 | Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4.10.2, Hono’s JWT Auth Middleware does not provide a built-in aud (Audience) verification option, which can cause confused-deputy / token-mix-up issues: an… | ||
| CVE-2023-51435 | Hig | 0.46 | 7.1 | 0.00 | Dec 29, 2023 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak. | ||
| CVE-2023-51431 | Hig | 0.46 | 7.0 | 0.00 | Dec 29, 2023 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions. | ||
| CVE-2023-23426 | Med | 0.43 | 6.6 | 0.00 | Dec 29, 2023 | Some Honor products are affected by file writing vulnerability, successful exploitation could cause information disclosure. | ||
| CVE-2026-39408 | Hig | 0.42 | 7.5 | 0.01 | Apr 8, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows files to be written outside the configured output directory during static site generation. When using dynamic route parameters via… | ||
| CVE-2026-29087 | Hig | 0.42 | 7.5 | 0.00 | Mar 6, 2026 | @hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware protections (e.g. protecting /admin/*), inconsistent URL decoding can allow protected static… | ||
| CVE-2026-29045 | Hig | 0.42 | 7.5 | 0.00 | Mar 4, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protections (e.g. app.use('/admin/*', ...)), inconsistent URL decoding allowed protected static resources to… | ||
| CVE-2025-58362 | Hig | 0.42 | 7.5 | 0.01 | Sep 5, 2025 | Hono is a Web application framework that provides support for any JavaScript runtime. Versions 4.8.0 through 4.9.5 contain a flaw in the getPath utility function which could allow path confusion and potential bypass of proxy-level ACLs (e.g. Nginx location blocks). The original… | ||
| CVE-2024-32652 | Hig | 0.42 | 7.5 | 0.01 | Apr 19, 2024 | The adapter @hono/node-server allows you to run your Hono application on Node.js. Prior to 1.10.1, the application hangs when receiving a Host header with a value that `@hono/node-server` can't handle well. Invalid values are those that cannot be parsed by the `URL` as a… | ||
| CVE-2023-23424 | Med | 0.42 | 6.5 | 0.01 | Dec 29, 2023 | Some Honor products are affected by file writing vulnerability, successful exploitation could cause code execution | ||
| CVE-2026-31370 | Med | 0.41 | 6.3 | 0.00 | Apr 21, 2026 | Honor E APP is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2024-47151 | Med | 0.41 | 6.3 | 0.00 | Dec 26, 2024 | Some Honor products are affected by file writing vulnerability, successful exploitation could cause code execution | ||
| CVE-2024-8994 | Med | 0.40 | 6.2 | 0.00 | Dec 26, 2024 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | ||
| CVE-2024-8993 | Med | 0.40 | 6.2 | 0.00 | Dec 26, 2024 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | ||
| CVE-2024-47153 | Med | 0.40 | 6.2 | 0.00 | Dec 26, 2024 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | ||
| CVE-2026-54290 | Hig | 0.39 | 7.1 | 0.00 | Jun 22, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials: true and no explicit origin (the default wildcard), the CORS Middleware reflects the request's Origin and sends Access-Control-Allow-Credentials: true. Any… | ||
| CVE-2023-51429 | Med | 0.39 | 6.0 | 0.00 | Dec 29, 2023 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak. | ||
| CVE-2023-23441 | Med | 0.39 | 6.0 | 0.00 | Dec 29, 2023 | Some Honor products are affected by out of bounds read vulnerability, successful exploitation could cause information leak. | ||
| CVE-2024-47155 | Med | 0.36 | 5.5 | 0.00 | Dec 26, 2024 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | ||
| CVE-2024-47154 | Med | 0.36 | 5.5 | 0.00 | Dec 26, 2024 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | ||
| CVE-2026-59896 | Med | 0.35 | 6.5 | 0.00 | Jul 8, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a… | ||
| CVE-2025-71381 | Med | 0.35 | 6.5 | 0.00 | Jun 30, 2026 | Hono before 4.10.2 (fixed in 4.10.3) contains a flaw in its CORS middleware: when the origin is not set to "*", the middleware copies the Vary header from the incoming request into the response. Because Vary is a response header that should be managed by the server, an attacker… | ||
| CVE-2026-54288 | Med | 0.35 | 6.5 | 0.00 | Jun 22, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit Middleware trusts the request's Content-Length header to decide whether a body is within the limit. On AWS Lambda (API Gateway v1/v2, ALB, VPC Lattice, and… | ||
| CVE-2026-44456 | Med | 0.35 | 6.5 | 0.00 | May 13, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does not reliably enforce maxSize for requests without a usable Content-Length (e.g. Transfer-Encoding: chunked). Oversized requests can reach handlers and return… | ||
| CVE-2026-29085 | Med | 0.35 | 6.5 | 0.00 | Mar 4, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using streamSSE() in Streaming Helper, the event, id, and retry fields were not validated for carriage return (\r) or newline (\n) characters. Because the SSE… | ||
| CVE-2026-59895 | Med | 0.33 | 6.1 | 0.00 | Jul 8, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values… | ||
| CVE-2026-54286 | Med | 0.31 | 5.9 | 0.00 | Jun 22, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) in the request path decodes to \, which the Windows path resolver treats as a separator. serve-static then resolves a single URL… | ||
| CVE-2024-48913 | Med | 0.31 | 5.9 | 0.00 | Oct 15, 2024 | Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by a request without Content-Type header. Although the CSRF middleware verifies the Content-Type Header, Hono always considers a request without a Content-Type… | ||
| CVE-2023-51428 | Med | 0.30 | 4.6 | 0.00 | Dec 29, 2023 | Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak. | ||
| CVE-2023-51427 | Med | 0.30 | 4.6 | 0.00 | Dec 29, 2023 | Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak. | ||
| CVE-2023-51426 | Med | 0.30 | 4.6 | 0.00 | Dec 29, 2023 | Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak. | ||
| CVE-2023-23443 | Med | 0.30 | 4.6 | 0.00 | Dec 29, 2023 | Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak. | ||
| CVE-2023-23442 | Med | 0.30 | 4.6 | 0.00 | Dec 29, 2023 | Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak. | ||
| CVE-2023-51430 | Med | 0.29 | 4.4 | 0.00 | Dec 29, 2023 | Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak. | ||
| CVE-2026-69207 | Med | 0.28 | 5.3 | 0.01 | Aug 7, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in CORS middleware, hono/cors, is vulnerable to a regular expression denial of service (ReDoS). During a preflight OPTIONS request, the middleware parses the… | ||
| CVE-2026-56761 | Med | 0.28 | 4.3 | 0.00 | Jun 24, 2026 | hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers can craft specially crafted attribute keys containing characters like quotes or angle brackets… | ||
| CVE-2026-29086 | Med | 0.28 | 5.4 | 0.00 | Mar 4, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, the setCookie() utility did not validate semicolons (;), carriage returns (\r), or newline characters (\n) in the domain and path options when constructing the… |
- risk 0.64cvss 9.8epss 0.01
There is a heap overflow vulnerability in some Huawei smartphone, attackers can exploit this vulnerability to cause heap overflows due to improper restriction of operations within the bounds of a memory buffer.
- risk 0.60cvss 9.3epss 0.00
Some Honor products are affected by buffer overflow vulnerability, successful exploitation could cause code execution.
- risk 0.57cvss 8.8epss 0.00
Several services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistant with default or overly permissive security attributes, leading to a privilege escalation.
- risk 0.57cvss 8.8epss 0.00
There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently authenticate the device try to connect to it in certain scenario. Successful exploit could allow the attacker to spoof then connect to the band.
- risk 0.53cvss 8.1epss 0.00
There is a whitelist mechanism bypass in GameCenter ,successful exploitation of this vulnerability may affect service confidentiality and integrity.
- risk 0.53cvss 8.1epss 0.00
Phoneservice module is affected by code injection vulnerability, successful exploitation of this vulnerability may affect service confidentiality and integrity.
- risk 0.51cvss 7.8epss 0.00
AiAssistant is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability.
- risk 0.47cvss 7.3epss 0.00
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file
- risk 0.47cvss 7.3epss 0.00
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.
- risk 0.47cvss 7.3epss 0.00
Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.
- risk 0.46cvss 8.2epss 0.00
Hono is a Web application framework that provides support for any JavaScript runtime. In versions 4.12.0 and 4.12.1, when using the AWS Lambda adapter (`hono/aws-lambda`) behind an Application Load Balancer (ALB), the `getConnInfo()` function incorrectly selected the first value…
- risk 0.46cvss 8.2epss 0.00
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the algorithm specified in the JWT header to influence signature verification when the selected JWK did…
- risk 0.46cvss 8.2epss 0.00
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the JWT header’s alg value to influence signature verification when the selected JWK did not…
- risk 0.46cvss 8.1epss 0.00
Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4.10.2, Hono’s JWT Auth Middleware does not provide a built-in aud (Audience) verification option, which can cause confused-deputy / token-mix-up issues: an…
- risk 0.46cvss 7.1epss 0.00
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.
- risk 0.46cvss 7.0epss 0.00
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
- risk 0.43cvss 6.6epss 0.00
Some Honor products are affected by file writing vulnerability, successful exploitation could cause information disclosure.
- risk 0.42cvss 7.5epss 0.01
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows files to be written outside the configured output directory during static site generation. When using dynamic route parameters via…
- risk 0.42cvss 7.5epss 0.00
@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware protections (e.g. protecting /admin/*), inconsistent URL decoding can allow protected static…
- risk 0.42cvss 7.5epss 0.00
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protections (e.g. app.use('/admin/*', ...)), inconsistent URL decoding allowed protected static resources to…
- risk 0.42cvss 7.5epss 0.01
Hono is a Web application framework that provides support for any JavaScript runtime. Versions 4.8.0 through 4.9.5 contain a flaw in the getPath utility function which could allow path confusion and potential bypass of proxy-level ACLs (e.g. Nginx location blocks). The original…
- risk 0.42cvss 7.5epss 0.01
The adapter @hono/node-server allows you to run your Hono application on Node.js. Prior to 1.10.1, the application hangs when receiving a Host header with a value that `@hono/node-server` can't handle well. Invalid values are those that cannot be parsed by the `URL` as a…
- risk 0.42cvss 6.5epss 0.01
Some Honor products are affected by file writing vulnerability, successful exploitation could cause code execution
- risk 0.41cvss 6.3epss 0.00
Honor E APP is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.41cvss 6.3epss 0.00
Some Honor products are affected by file writing vulnerability, successful exploitation could cause code execution
- risk 0.40cvss 6.2epss 0.00
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
- risk 0.40cvss 6.2epss 0.00
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
- risk 0.40cvss 6.2epss 0.00
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
- risk 0.39cvss 7.1epss 0.00
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials: true and no explicit origin (the default wildcard), the CORS Middleware reflects the request's Origin and sends Access-Control-Allow-Credentials: true. Any…
- risk 0.39cvss 6.0epss 0.00
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.
- risk 0.39cvss 6.0epss 0.00
Some Honor products are affected by out of bounds read vulnerability, successful exploitation could cause information leak.
- risk 0.36cvss 5.5epss 0.00
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
- risk 0.36cvss 5.5epss 0.00
Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.
- risk 0.35cvss 6.5epss 0.00
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server-side rendering, allowing createContext, useContext, jsxRenderer, or useRequestContext data from a…
- risk 0.35cvss 6.5epss 0.00
Hono before 4.10.2 (fixed in 4.10.3) contains a flaw in its CORS middleware: when the origin is not set to "*", the middleware copies the Vary header from the incoming request into the response. Because Vary is a response header that should be managed by the server, an attacker…
- risk 0.35cvss 6.5epss 0.00
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit Middleware trusts the request's Content-Length header to decide whether a body is within the limit. On AWS Lambda (API Gateway v1/v2, ALB, VPC Lattice, and…
- risk 0.35cvss 6.5epss 0.00
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does not reliably enforce maxSize for requests without a usable Content-Length (e.g. Transfer-Encoding: chunked). Oversized requests can reach handlers and return…
- risk 0.35cvss 6.5epss 0.00
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using streamSSE() in Streaming Helper, the event, id, and retry fields were not validated for carriage return (\r) or newline (\n) characters. Because the SSE…
- risk 0.33cvss 6.1epss 0.00
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values…
- risk 0.31cvss 5.9epss 0.00
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) in the request path decodes to \, which the Windows path resolver treats as a separator. serve-static then resolves a single URL…
- risk 0.31cvss 5.9epss 0.00
Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by a request without Content-Type header. Although the CSRF middleware verifies the Content-Type Header, Hono always considers a request without a Content-Type…
- risk 0.30cvss 4.6epss 0.00
Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.
- risk 0.30cvss 4.6epss 0.00
Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.
- risk 0.30cvss 4.6epss 0.00
Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.
- risk 0.30cvss 4.6epss 0.00
Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.
- risk 0.30cvss 4.6epss 0.00
Some Honor products are affected by type confusion vulnerability, successful exploitation could cause information leak.
- risk 0.29cvss 4.4epss 0.00
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause information leak.
- risk 0.28cvss 5.3epss 0.01
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in CORS middleware, hono/cors, is vulnerable to a regular expression denial of service (ReDoS). During a preflight OPTIONS request, the middleware parses the…
- risk 0.28cvss 4.3epss 0.00
hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers can craft specially crafted attribute keys containing characters like quotes or angle brackets…
- risk 0.28cvss 5.4epss 0.00
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, the setCookie() utility did not validate semicolons (;), carriage returns (\r), or newline characters (\n) in the domain and path options when constructing the…
Page 1 of 3