Exposure of Hono
Web frameworks18
exposure score
72
sites use
0
exploited
0
critical
CVEs
52 resultsCVE-2024-32869MEDIUMHono vulnerable to Restricted Directory Traversal in serveStatic with denoEPSS 0.6%CVE-2023-50710MEDIUMHono's named path parameters can be overridden in TrieRouterEPSS 0.6%CVE-2026-29045HIGHHono: Arbitrary file access via serveStatic vulnerabilityEPSS 0.6%CVE-2026-69207MEDIUMHono: ReDoS in CORS middleware via Access-Control-Request-HeadersEPSS 0.6%CVE-2025-58362HIGHHono contains a flaw in URL path parsing, potentially leading to path confusionEPSS 0.5%CVE-2026-84364MEDIUMHono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustionEPSS 0.5%CVE-2026-24472MEDIUMHono cache middleware ignores "Cache-Control: private" leading to Web Cache DeceptionEPSS 0.5%CVE-2026-71848MEDIUMHono: Algorithmic Complexity DoS in Language MiddlewareEPSS 0.5%CVE-2026-24473MEDIUMHono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)EPSS 0.5%CVE-2026-39408MEDIUMHono has a path traversal in toSSG() allows writing files outside the output directoryEPSS 0.4%CVE-2025-59139MEDIUMHono has Body Limit Middleware BypassEPSS 0.4%CVE-2026-39407MEDIUMHono has a middleware bypass via repeated slashes in serveStaticEPSS 0.4%CVE-2026-84363MEDIUMHono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentialsEPSS 0.4%CVE-2026-84365MEDIUMHono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directoryEPSS 0.4%CVE-2026-42349HIGHClerk: Authorization bypass when combining organization, billing, or reverification checksEPSS 0.4%CVE-2026-54286MEDIUMHono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)EPSS 0.4%CVE-2026-56762MEDIUMHono - Missing Cookie Name Validation in setCookie()EPSS 0.4%CVE-2026-39409MEDIUMHono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addressesEPSS 0.4%CVE-2025-62610HIGHHono Improperly Authorizes JWT Audience ValidationEPSS 0.4%CVE-2026-71849LOWHono: Proxy Helper does not remove response headers listed in the `Connection` headerEPSS 0.4%