Skip to content

Hono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass

High severity GitHub Reviewed Published Jan 13, 2026 in honojs/hono • Updated Jan 13, 2026

No closed alerts for this advisory

Give feedback on Dependabot alerts