Vulnerabilidades en honojs
52 resultadosAnálisis Vexday
Honejs apresenta 42 vulnerabilidades catalogadas, com 17 delas publicadas nos últimos 90 dias, indicando atividade recente significativa na superfície de risco. Não há registros de exploração em ataques ativos (KEV) nem vulnerabilidades críticas pelo CVSS, porém a fraqueza dominante é CWE-22 (path traversal), típica de impacto moderado que merece atenção em ambientes onde o controle de acesso a arquivos é crítico.
CVE-2026-71850MEDIUMHono: `memo()` retains SSR output across requests, leading to cross-user data disclosureEPSS 0.3%CVE-2026-29086MEDIUMHono: Cookie Attribute Injection via Unsanitized domain and path in setCookie()EPSS 0.3%CVE-2026-47673MEDIUMHono: JWT middleware accepts any Authorization scheme, not only BearerEPSS 0.3%CVE-2024-43787MEDIUMHono CSRF middleware can be bypassed using crafted Content-Type headerEPSS 0.2%CVE-2026-93981LOWhono/jsx before 4.13.7 Cross-Site Scripting via Unescaped StringsEPSS 0.2%CVE-2026-44455MEDIUMHono: Unvalidated JSX Tag Names in hono/jsx May Allow HTML InjectionEPSS 0.2%CVE-2026-81888MEDIUM@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linkingEPSS 0.2%CVE-2026-59897MEDIUMHono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplicationEPSS 0.2%CVE-2026-54289MEDIUMHono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the restEPSS 0.2%CVE-2026-22817HIGHJWT Algorithm Confusion via Unsafe Default (HS256) in Hono JWT Middleware Allows Token Forgery and Auth BypassEPSS 0.2%CVE-2026-54288MEDIUMHono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`EPSS 0.1%CVE-2026-22818HIGHJWT algorithm confusion in Hono JWK Auth Middleware when JWK lacks "alg" (untrusted header.alg fallback)EPSS 0.1%