Catalog / Hono

Hono security advisories

All 51 advisories Hono has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.

Advisories
5145 carry a CVE
high
7
medium
41
low
3
Fix in the archive
44of 51 matched to a release
Oldest
14 Dec 20232.7 years ago

7 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Newest first

Every product
CVE-2026-84363medium

Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials

GHSA-crvj-82cr-hjcxFixed in 4.13.5
CVE-2026-84365medium

Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory

GHSA-gqvv-2mrq-wpjvFixed in 4.13.5
CVE-2026-59896medium

hono/jsx does not isolate context per request, leading to cross-request data disclosure

GHSA-hvrm-45r6-mjfjFixed in 4.12.27
CVE-2026-59897medium

API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication

GHSA-xgm2-5f3f-mvvcFixed in 4.12.27
CVE-2026-54287medium

AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice

GHSA-j6c9-x7qj-28xfFixed in 4.12.25
CVE-2026-54289medium

Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest

GHSA-wgpf-jwqj-8h8pFixed in 4.12.25
CVE-2026-54290high

CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard

GHSA-88fw-hqm2-52qcFixed in 4.12.25
CVE-2026-47675medium

Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection

GHSA-3hrh-pfw6-9m5xFixed in 4.12.21
CVE-2026-47676medium

app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths

GHSA-2gcr-mfcq-wcc3Fixed in 4.12.21
CVE-2026-44457medium

Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakage

GHSA-p77w-8qqv-26rmFixed in 4.12.18
CVE-2026-24472medium

Cache Middleware ignores `Cache-Control: private` leading to Web Cache Deception

GHSA-6wqw-2p9w-4vw4Fixed in 4.11.7
CVE-2026-24771medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in hono

GHSA-9r54-q6cx-xmh5Fixed in 4.11.7
CVE-2026-22817high

JWT Algorithm Confusion via Unsafe Default (HS256) in Hono JWT Middleware Allows Token Forgery and Auth Bypass

GHSA-f67f-6cw9-8mq4Fixed in 4.11.4
CVE-2026-22818high

JWT algorithm confusion in Hono JWK Auth Middleware when JWK lacks "alg" (untrusted header.alg fallback)

GHSA-3vhc-576x-3qv4Fixed in 4.11.4
CVE-2025-62610high

Improper Authorization in hono

GHSA-m732-5p4w-x69gFixed in 4.10.2, not held here
CVE-2025-59139medium

Body Limit Middleware Bypass

GHSA-92vj-g62v-jqhhFixed in 4.9.7, not held here
CVE-2025-58362high

Flaw in URL path parsing could cause path confusion

GHSA-9hp6-4448-45g2Fixed in 4.9.6, not held here
CVE-2024-48913medium

Bypass CSRF Middleware by a request without Content-Type header

GHSA-2234-fmw7-43wrFixed in 4.6.5, not held here
CVE-2024-43787medium

Bypass CSRF middleware

GHSA-rpfr-3m35-5vx5Fixed in 4.5.8, not held here
CVE-2024-32869medium

Restricted Directory Traversal in serveStatic with deno

GHSA-3mpf-rcc7-5347Fixed in 4.2.7, not held here
CVE-2023-50710medium

Named path parameters can be overridden in TrieRouter

GHSA-f6gv-hh8j-q8vqFixed in 3.11.7, not held here