Security: honojs/hono
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the restGHSA-wgpf-jwqj-8h8p published
Jun 9, 2026 by yusukebeModerate -
AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and LatticeGHSA-j6c9-x7qj-28xf published
Jun 9, 2026 by yusukebeModerate -
app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded pathsGHSA-2gcr-mfcq-wcc3 published
May 19, 2026 by yusukebeModerate -
IP Restriction bypasses static deny rules for non-canonical IPv6GHSA-xrhx-7g5j-rcj5 published
May 19, 2026 by yusukebeModerate -
Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injectionGHSA-3hrh-pfw6-9m5x published
May 19, 2026 by yusukebeModerate -
JWT middleware accepts any Authorization scheme, not only BearerGHSA-f577-qrjj-4474 published
May 19, 2026 by yusukebeModerate -
Improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()GHSA-hm8q-7f3q-5f36 published
May 6, 2026 by yusukebeLow -
bodyLimit() can be bypassed for chunked / unknown-length requestsGHSA-9vqf-7f2p-gf9v published
Apr 30, 2026 by yusukebeModerate -
CSS Declaration Injection via Style Object Values in JSX SSRGHSA-qp7p-654g-cw7p published
May 6, 2026 by yusukebeModerate -
Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakageGHSA-p77w-8qqv-26rm published
May 6, 2026 by yusukebeModerate