VYPR

Vendor CVEs

Honojs

All CVEs

109 total · sorted by risk
  • CVE-2025-2197MedApr 17, 2025
    risk 0.28cvss 4.3epss 0.00

    Browser is affected by type confusion vulnerability, successful exploitation of this vulnerability may affect service availability.

  • CVE-2024-32869MedApr 23, 2024
    risk 0.28cvss 5.3epss 0.01

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.2.7, when using serveStatic with deno, it is possible to traverse the directory where `main.ts` is located. This can result in retrieval of unexpected files. Version 4.2.7…

  • CVE-2024-23340MedJan 22, 2024
    risk 0.28cvss 5.3epss 0.01

    @hono/node-server is an adapter that allows users to run Hono applications on Node.js. Since v1.3.0, @hono/node-server has used its own Request object with `url` behavior that is unexpected. In the standard API, if the URL contains `..`, here called "double dots", the URL string…

  • CVE-2026-73565MedAug 13, 2026
    risk 0.27cvss 5.3epss 0.00

    @hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request to an upgradeWebSocket route with a missing or malformed Sec-WebSocket-Key header causes src/websocket.ts to retain the request's IncomingMessage in waiterMap…

  • CVE-2026-71848MedAug 7, 2026
    risk 0.27cvss 5.3epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.0 to 4.12.33, the languageDetector middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen…

  • CVE-2026-56762MedJun 23, 2026
    risk 0.27cvss 5.3epss 0.00

    Hono before 4.12.12 does not validate cookie names on the write path in the setCookie(), serialize(), and serializeSigned() functions, allowing invalid characters such as control characters (e.g. \r or \n) when an application passes a user-controlled cookie name. This can…

  • CVE-2026-54287MedJun 22, 2026
    risk 0.27cvss 5.3epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, the ALB single-header response and the VPC Lattice v2 response join multiple Set-Cookie headers into one comma-separated value. Because commas also appear…

  • CVE-2026-47676MedMay 28, 2026
    risk 0.27cvss 5.3epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the incoming request path using the raw URL pathname, while route matching is performed against the percent-decoded path. This…

  • CVE-2026-47674MedMay 28, 2026
    risk 0.27cvss 5.3epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restriction) compares incoming IP addresses against configured deny and allow rules using string equality after partial normalization.…

  • CVE-2026-44457MedMay 13, 2026
    risk 0.27cvss 5.3epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware does not skip caching for responses that declare per-user variance via Vary: Authorization or Vary: Cookie. As a result, a response cached for one…

  • CVE-2026-39409MedApr 8, 2026
    risk 0.27cvss 5.3epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() does not canonicalize IPv4-mapped IPv6 client addresses (e.g. ::ffff:127.0.0.1) before applying IPv4 allow or deny rules. In environments such as Node.js…

  • CVE-2026-39407MedApr 8, 2026
    risk 0.27cvss 5.3epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path. When route-based middleware…

  • CVE-2026-39406MedApr 8, 2026
    risk 0.27cvss 5.3epss 0.00

    @hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path. When route-based middleware (e.g., /admin/*) is used…

  • CVE-2026-24473MedJan 27, 2026
    risk 0.27cvss 5.3epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Serve static Middleware for the Cloudflare Workers adapter contains an information disclosure vulnerability that may allow attackers to read arbitrary keys from the…

  • CVE-2026-24472MedJan 27, 2026
    risk 0.27cvss 5.3epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Cache Middleware contains an information disclosure vulnerability caused by improper handling of HTTP cache control directives. The middleware does not respect standard…

  • CVE-2025-59139MedSep 12, 2025
    risk 0.27cvss 5.3epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. In versions prior to 4.9.7, a flaw in the `bodyLimit` middleware could allow bypassing the configured request body size limit when conflicting HTTP headers were present. The middleware…

  • CVE-2025-57839MedOct 20, 2025
    risk 0.26cvss 4.0epss 0.00

    Photo module is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2025-57838MedOct 20, 2025
    risk 0.26cvss 4.0epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-8992MedDec 26, 2024
    risk 0.26cvss 4.0epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

  • CVE-2024-47148MedDec 26, 2024
    risk 0.26cvss 4.0epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

  • CVE-2024-43787MedAug 22, 2024
    risk 0.26cvss 5.0epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypassed using crafted Content-Type header. MIME types are case insensitive, but isRequestedByFormElementRe only matches lower-case. As a result, attacker can bypass…

  • CVE-2023-6939MedDec 29, 2023
    risk 0.26cvss 4.0epss 0.00

    Some Honor products are affected by type confusion vulnerability, successful exploitation could cause denial of service.

  • CVE-2023-23439MedDec 29, 2023
    risk 0.26cvss 4.0epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

  • CVE-2023-23438MedDec 29, 2023
    risk 0.26cvss 4.0epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions

  • CVE-2023-23429MedDec 29, 2023
    risk 0.26cvss 4.0epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

  • CVE-2023-23427MedDec 29, 2023
    risk 0.26cvss 4.0epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

  • CVE-2023-23435MedDec 29, 2023
    risk 0.26cvss 4.0epss 0.00

    Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file

  • CVE-2023-23434MedDec 29, 2023
    risk 0.26cvss 4.0epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

  • CVE-2023-23433MedDec 29, 2023
    risk 0.26cvss 4.0epss 0.00

    Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file.

  • CVE-2026-71850MedAug 7, 2026
    risk 0.24cvss 4.8epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from hono/jsx retains the result of a server side render and reuses it for later renders with comparator equal props, and request scoped values read inside the…

  • CVE-2026-59897MedJul 8, 2026
    risk 0.24cvss 4.8epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request header value because it de-duplicates values using a substring comparison instead of an exact…

  • CVE-2026-54289MedJun 22, 2026
    risk 0.24cvss 4.8epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Edge, CloudFront delivers a request header that appears more than once as several separate entries. The adapter writes each value with Headers.set instead of…

  • CVE-2026-47673MedMay 28, 2026
    risk 0.24cvss 4.8epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify that the Authorization header value uses theBearer scheme. Any two-part header value — regardless of the scheme name in the first…

  • CVE-2026-44455MedMay 13, 2026
    risk 0.24cvss 4.7epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, Improper handling of JSX element tag names in hono/jsx allowed unvalidated tag names to be directly inserted into the generated HTML output. When untrusted input is used as a…

  • CVE-2026-39410MedApr 8, 2026
    risk 0.24cvss 4.8epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy between browser cookie parsing and parse() handling allows cookie prefix protections to be bypassed. Cookie names that are treated as distinct by the browser may…

  • CVE-2026-24771MedJan 27, 2026
    risk 0.24cvss 4.7epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, a Cross-Site Scripting (XSS) vulnerability exists in the `ErrorBoundary` component of the hono/jsx library. Under certain usage patterns, untrusted user-controlled…

  • CVE-2026-24398MedJan 27, 2026
    risk 0.24cvss 4.8epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, IP Restriction Middleware in Hono is vulnerable to an IP address validation bypass. The `IPV4_REGEX` pattern and `convertIPv4ToBinary` function in `src/utils/ipaddr.ts`…

  • CVE-2026-47675MedMay 28, 2026
    risk 0.21cvss 4.3epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path options against characters that corrupt Set-Cookie header syntax (;, \r, \n), but does not apply the same…

  • CVE-2026-44458MedMay 13, 2026
    risk 0.21cvss 4.3epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer escapes style attribute object values for HTML but not for CSS. Untrusted input in a style object value or property name can therefore inject additional CSS…

  • CVE-2026-31369LowApr 21, 2026
    risk 0.21cvss 3.2epss 0.00

    PcManager is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability

  • CVE-2024-47150LowDec 26, 2024
    risk 0.21cvss 3.3epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

  • CVE-2024-47149LowDec 26, 2024
    risk 0.21cvss 3.3epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

  • CVE-2024-47156LowDec 26, 2024
    risk 0.21cvss 3.3epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

  • CVE-2023-51432LowDec 29, 2023
    risk 0.21cvss 3.2epss 0.00

    Some Honor products are affected by out of bounds read vulnerability, successful exploitation could cause information leak.

  • CVE-2023-23440LowDec 29, 2023
    risk 0.21cvss 3.3epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

  • CVE-2023-23437LowDec 29, 2023
    risk 0.21cvss 3.3epss 0.00

    Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak

  • CVE-2023-23430LowDec 29, 2023
    risk 0.21cvss 3.3epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

  • CVE-2023-23428LowDec 29, 2023
    risk 0.21cvss 3.3epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

  • CVE-2023-50710MedDec 14, 2023
    risk 0.20cvss 4.2epss 0.01

    Hono is a web framework written in TypeScript. Prior to version 3.11.7, clients may override named path parameter values from previous requests if the application is using TrieRouter. So, there is a risk that a privileged user may use unintended parameters when deleting REST API…

  • CVE-2025-57837LowOct 20, 2025
    risk 0.19cvss 2.9epss 0.00

    Tileservice module is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.