Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-59895 |
|
Cross-Site Scripting (XSS) in hono (CVE-2026-59895)
cross-site scripting in hono (CVE-2026-59895). Risk of unauthorized operations or information disclosure. Exploitable via ``class``. Mitigation: upgrade to `4.12.27` or later.
|
| CVE-2026-59896 |
|
Vulnerability in hono (CVE-2026-59896)
vulnerability in hono (CVE-2026-59896). Confidential information can be exposed externally. Exploitable via ``await``. Mitigation: upgrade to `4.12.27` or later.
|
| CVE-2026-59897 |
|
Vulnerability in hono (CVE-2026-59897)
vulnerability in hono (CVE-2026-59897). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.12.27` or later.
|
| CVE-2026-47673 |
|
Vulnerability in hono (CVE-2026-47673)
vulnerability in hono (CVE-2026-47673). Risk of unauthorized operations or information disclosure. Exploitable via ``jwt``. Mitigation: upgrade to `4.12.21` or later.
|
| CVE-2026-47674 |
|
Vulnerability in hono (CVE-2026-47674)
vulnerability in hono (CVE-2026-47674). Risk of unauthorized operations or information disclosure. Exploitable via ``getIP``. Mitigation: upgrade to `4.12.21` or later.
|
| CVE-2026-47675 |
|
Vulnerability in hono (CVE-2026-47675)
vulnerability in hono (CVE-2026-47675). Risk of unauthorized operations or information disclosure. Exploitable via ``domain``. Mitigation: upgrade to `4.12.21` or later.
|
| CVE-2026-47676 |
|
Vulnerability in hono (CVE-2026-47676)
vulnerability in hono (CVE-2026-47676). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.12.21` or later.
|
| CVE-2026-44455 |
|
Vulnerability in hono (CVE-2026-44455)
vulnerability in hono (CVE-2026-44455). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.12.16` or later.
|
| CVE-2026-44456 |
|
Vulnerability in hono (CVE-2026-44456)
vulnerability in hono (CVE-2026-44456). Risk of unauthorized operations or information disclosure. Exploitable via ``maxSize``. Mitigation: upgrade to `4.12.16` or later.
|
| CVE-2026-44458 |
|
Vulnerability in hono (CVE-2026-44458)
vulnerability in hono (CVE-2026-44458). Risk of unauthorized operations or information disclosure. Exploitable via ``style``. Mitigation: upgrade to `4.12.18` or later.
|
| CVE-2026-44459 |
|
Vulnerability in hono (CVE-2026-44459)
vulnerability in hono (CVE-2026-44459). Risk of unauthorized operations or information disclosure. Exploitable via ``exp``. Mitigation: upgrade to `4.12.18` or later.
|
| CVE-2026-44457 |
|
Vulnerability in hono (CVE-2026-44457)
vulnerability in hono (CVE-2026-44457). Risk of unauthorized operations or information disclosure. Exploitable via ``private``. Mitigation: upgrade to `4.12.18` or later.
|
| CVE-2026-56761 |
|
Cross-Site Scripting (XSS) in hono (CVE-2026-56761)
cross-site scripting in hono (CVE-2026-56761). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.12.14` or later.
|
| CVE-2026-39410 |
|
Vulnerability in hono (CVE-2026-39410)
vulnerability in hono (CVE-2026-39410). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.12.12` or later.
|
| CVE-2026-39406 |
|
Path Traversal in hono (CVE-2026-39406)
path traversal in hono (CVE-2026-39406). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.19.13` or later.
|
| CVE-2026-39407 |
|
Path Traversal in hono (CVE-2026-39407)
path traversal in hono (CVE-2026-39407). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.12.12` or later.
|
| CVE-2026-39408 |
|
Path Traversal in path-traversal (CVE-2026-39408)
path traversal in path-traversal (CVE-2026-39408). Confidential information can be exposed externally. Mitigation: upgrade to `4.12.12` or later.
|
| CVE-2026-39409 |
|
Vulnerability in hono (CVE-2026-39409)
vulnerability in hono (CVE-2026-39409). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `4.12.12` or later.
|