Vulnerabilidades em honojs

52 resultados
Análise Vexday

Honejs apresenta 42 vulnerabilidades catalogadas, com 17 delas publicadas nos últimos 90 dias, indicando atividade recente significativa na superfície de risco. Não há registros de exploração em ataques ativos (KEV) nem vulnerabilidades críticas pelo CVSS, porém a fraqueza dominante é CWE-22 (path traversal), típica de impacto moderado que merece atenção em ambientes onde o controle de acesso a arquivos é crítico.

CVE-2024-32652HIGH@hono/node-server contains Denial of Service risk when receiving Host header that cannot be parsedEPSS 0.9%CVE-2024-23340MEDIUM@hono/node-server can't handle "double dots" in URLEPSS 0.7%CVE-2024-32869MEDIUMHono vulnerable to Restricted Directory Traversal in serveStatic with denoEPSS 0.6%CVE-2023-50710MEDIUMHono's named path parameters can be overridden in TrieRouterEPSS 0.6%CVE-2025-58362HIGHHono contains a flaw in URL path parsing, potentially leading to path confusionEPSS 0.5%CVE-2026-39408MEDIUMHono has a path traversal in toSSG() allows writing files outside the output directoryEPSS 0.5%CVE-2026-29045HIGHHono: Arbitrary file access via serveStatic vulnerabilityEPSS 0.5%CVE-2026-69207MEDIUMHono: ReDoS in CORS middleware via Access-Control-Request-HeadersEPSS 0.5%CVE-2026-24472MEDIUMHono cache middleware ignores "Cache-Control: private" leading to Web Cache DeceptionEPSS 0.5%CVE-2026-39407MEDIUMHono has a middleware bypass via repeated slashes in serveStaticEPSS 0.5%CVE-2025-59139MEDIUMHono has Body Limit Middleware BypassEPSS 0.4%CVE-2026-24473MEDIUMHono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)EPSS 0.4%CVE-2026-54286MEDIUMHono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)EPSS 0.4%CVE-2026-84364MEDIUMHono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustionEPSS 0.4%CVE-2026-73565MEDIUM@hono/node-server: Unauthenticated memory-leak DoS via aborted WebSocket handshakeEPSS 0.4%CVE-2025-62610HIGHHono Improperly Authorizes JWT Audience ValidationEPSS 0.4%CVE-2026-39406MEDIUM@hono/node-server has a middleware bypass via repeated slashes in serveStaticEPSS 0.4%CVE-2026-84363MEDIUMHono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentialsEPSS 0.3%CVE-2026-39409MEDIUMHono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addressesEPSS 0.3%CVE-2026-54290HIGHHono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcardEPSS 0.3%