Vulnerabilidades en honojs
52 resultadosAnálisis Vexday
Honejs apresenta 42 vulnerabilidades catalogadas, com 17 delas publicadas nos últimos 90 dias, indicando atividade recente significativa na superfície de risco. Não há registros de exploração em ataques ativos (KEV) nem vulnerabilidades críticas pelo CVSS, porém a fraqueza dominante é CWE-22 (path traversal), típica de impacto moderado que merece atenção em ambientes onde o controle de acesso a arquivos é crítico.
CVE-2024-32652HIGH@hono/node-server contains Denial of Service risk when receiving Host header that cannot be parsedEPSS 0.9%CVE-2024-23340MEDIUM@hono/node-server can't handle "double dots" in URLEPSS 0.7%CVE-2024-32869MEDIUMHono vulnerable to Restricted Directory Traversal in serveStatic with denoEPSS 0.6%CVE-2023-50710MEDIUMHono's named path parameters can be overridden in TrieRouterEPSS 0.6%CVE-2026-69207MEDIUMHono: ReDoS in CORS middleware via Access-Control-Request-HeadersEPSS 0.6%CVE-2026-29045HIGHHono: Arbitrary file access via serveStatic vulnerabilityEPSS 0.6%CVE-2025-58362HIGHHono contains a flaw in URL path parsing, potentially leading to path confusionEPSS 0.5%CVE-2026-84364MEDIUMHono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustionEPSS 0.5%CVE-2026-73565MEDIUM@hono/node-server: Unauthenticated memory-leak DoS via aborted WebSocket handshakeEPSS 0.5%CVE-2026-24472MEDIUMHono cache middleware ignores "Cache-Control: private" leading to Web Cache DeceptionEPSS 0.5%CVE-2026-71848MEDIUMHono: Algorithmic Complexity DoS in Language MiddlewareEPSS 0.5%CVE-2026-24473MEDIUMHono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)EPSS 0.5%CVE-2026-39407MEDIUMHono has a middleware bypass via repeated slashes in serveStaticEPSS 0.4%CVE-2025-59139MEDIUMHono has Body Limit Middleware BypassEPSS 0.4%CVE-2026-39408MEDIUMHono has a path traversal in toSSG() allows writing files outside the output directoryEPSS 0.4%CVE-2026-84363MEDIUMHono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentialsEPSS 0.4%CVE-2026-84365MEDIUMHono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directoryEPSS 0.4%CVE-2026-54286MEDIUMHono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)EPSS 0.4%CVE-2026-29087HIGH@hono/node-server: Authorization bypass for protected static paths via encoded slashes in Serve Static MiddlewareEPSS 0.4%CVE-2026-39409MEDIUMHono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addressesEPSS 0.4%