Exposure of Hono
Web frameworks18
exposure score
72
sites use
0
exploited
0
critical
CVEs
52 resultsCVE-2026-56763MEDIUMHono - Prototype Pollution via __proto__ Key in parseBody with dot OptionEPSS 0.3%CVE-2026-29086MEDIUMHono: Cookie Attribute Injection via Unsanitized domain and path in setCookie()EPSS 0.3%CVE-2026-71850MEDIUMHono: `memo()` retains SSR output across requests, leading to cross-user data disclosureEPSS 0.3%CVE-2026-47673MEDIUMHono: JWT middleware accepts any Authorization scheme, not only BearerEPSS 0.3%CVE-2024-43787MEDIUMHono CSRF middleware can be bypassed using crafted Content-Type headerEPSS 0.2%CVE-2026-93981LOWhono/jsx before 4.13.7 Cross-Site Scripting via Unescaped StringsEPSS 0.2%CVE-2026-44455MEDIUMHono: Unvalidated JSX Tag Names in hono/jsx May Allow HTML InjectionEPSS 0.2%CVE-2026-59897MEDIUMHono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplicationEPSS 0.2%CVE-2026-54289MEDIUMHono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the restEPSS 0.2%CVE-2026-22817HIGHJWT Algorithm Confusion via Unsafe Default (HS256) in Hono JWT Middleware Allows Token Forgery and Auth BypassEPSS 0.2%CVE-2026-54288MEDIUMHono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`EPSS 0.1%CVE-2026-22818HIGHJWT algorithm confusion in Hono JWK Auth Middleware when JWK lacks "alg" (untrusted header.alg fallback)EPSS 0.1%