Vulnerabilidades en honojs
52 resultadosAnálisis Vexday
Honejs apresenta 42 vulnerabilidades catalogadas, com 17 delas publicadas nos últimos 90 dias, indicando atividade recente significativa na superfície de risco. Não há registros de exploração em ataques ativos (KEV) nem vulnerabilidades críticas pelo CVSS, porém a fraqueza dominante é CWE-22 (path traversal), típica de impacto moderado que merece atenção em ambientes onde o controle de acesso a arquivos é crítico.
CVE-2026-39406MEDIUM@hono/node-server has a middleware bypass via repeated slashes in serveStaticEPSS 0.4%CVE-2025-62610HIGHHono Improperly Authorizes JWT Audience ValidationEPSS 0.4%CVE-2026-71849LOWHono: Proxy Helper does not remove response headers listed in the `Connection` headerEPSS 0.4%CVE-2026-24771MEDIUMHono has a Cross-site Scripting vulnerabilityEPSS 0.4%CVE-2026-24398MEDIUMHono's IPv4 address validation bypass in IP Restriction Middleware allows IP spoofingEPSS 0.4%CVE-2026-27700HIGHHono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfoEPSS 0.3%CVE-2026-44458MEDIUMHono: CSS Declaration Injection via Style Object Values in JSX SSREPSS 0.3%CVE-2026-39410MEDIUMHono has a non-breaking space prefix bypass in cookie name handling in getCookie()EPSS 0.3%CVE-2026-44457MEDIUMHono: Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakageEPSS 0.3%CVE-2026-47676MEDIUMHono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded pathsEPSS 0.3%CVE-2026-54290HIGHHono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcardEPSS 0.3%CVE-2026-59895MEDIUMHono: Server-Side XSS via JSX Escaping Bypass in cx() UtilityEPSS 0.3%CVE-2024-48913MEDIUMHono vulnerable to bypass of CSRF Middleware by a request without Content-Type header.EPSS 0.3%CVE-2026-47674MEDIUMHono: IP Restriction bypasses static deny rules for non-canonical IPv6EPSS 0.3%CVE-2026-54287MEDIUMHono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and LatticeEPSS 0.3%CVE-2026-59896MEDIUMhono/jsx does not isolate context per request, leading to cross-request data disclosureEPSS 0.3%CVE-2026-29085MEDIUMHono: SSE Control Field Injection via CR/LF in writeSSE()EPSS 0.3%CVE-2026-44456MEDIUMHono: bodyLimit() can be bypassed for chunked / unknown-length requestsEPSS 0.3%CVE-2026-47675MEDIUMHono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injectionEPSS 0.3%CVE-2026-44459LOWHono: Improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()EPSS 0.3%