Exposure of Hono

Web frameworks
18
exposure score
72
sites use
0
exploited
0
critical

CVEs

52 results
CVE-2026-24771MEDIUMHono has a Cross-site Scripting vulnerabilityEPSS 0.4%CVE-2026-24398MEDIUMHono's IPv4 address validation bypass in IP Restriction Middleware allows IP spoofingEPSS 0.4%CVE-2026-27700HIGHHono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfoEPSS 0.3%CVE-2026-44458MEDIUMHono: CSS Declaration Injection via Style Object Values in JSX SSREPSS 0.3%CVE-2026-39410MEDIUMHono has a non-breaking space prefix bypass in cookie name handling in getCookie()EPSS 0.3%CVE-2026-47676MEDIUMHono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded pathsEPSS 0.3%CVE-2026-44457MEDIUMHono: Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakageEPSS 0.3%CVE-2026-54290HIGHHono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcardEPSS 0.3%CVE-2026-59895MEDIUMHono: Server-Side XSS via JSX Escaping Bypass in cx() UtilityEPSS 0.3%CVE-2024-48913MEDIUMHono vulnerable to bypass of CSRF Middleware by a request without Content-Type header.EPSS 0.3%CVE-2026-54287MEDIUMHono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and LatticeEPSS 0.3%CVE-2026-47674MEDIUMHono: IP Restriction bypasses static deny rules for non-canonical IPv6EPSS 0.3%CVE-2026-29085MEDIUMHono: SSE Control Field Injection via CR/LF in writeSSE()EPSS 0.3%CVE-2026-59896MEDIUMhono/jsx does not isolate context per request, leading to cross-request data disclosureEPSS 0.3%CVE-2026-56764MEDIUMHono - Timing Attack in basicAuth and bearerAuth MiddlewareEPSS 0.3%CVE-2026-56761MEDIUMhono - HTML Injection via Improper JSX Attribute Name Handling in SSREPSS 0.3%CVE-2025-71381MEDIUMHono - Vary Header Injection in CORS MiddlewareEPSS 0.3%CVE-2026-44456MEDIUMHono: bodyLimit() can be bypassed for chunked / unknown-length requestsEPSS 0.3%CVE-2026-47675MEDIUMHono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injectionEPSS 0.3%CVE-2026-44459LOWHono: Improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()EPSS 0.3%