Security: honojs/hono
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
`memo()` retains SSR output across requests, leading to cross-user data disclosureGHSA-f23p-vx2j-j53r published
Aug 3, 2026 by yusukebeModerate -
Proxy Helper does not remove response headers listed in the `Connection` headerGHSA-79qm-7rj5-m7r9 published
Aug 3, 2026 by yusukebeLow -
Algorithmic Complexity DoS in Language MiddlewareGHSA-54fx-42gc-7vw4 published
Aug 3, 2026 by yusukebeModerate -
ReDoS in CORS middleware via Access-Control-Request-HeadersGHSA-8j4g-w8fx-2239 published
Aug 3, 2026 by yusukebeModerate -
API Gateway v1 adapter can drop a distinct repeated request header value during de-duplicationGHSA-xgm2-5f3f-mvvc published
Jun 23, 2026 by yusukebeModerate -
Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)GHSA-wwfh-h76j-fc44 published
Jun 9, 2026 by yusukebeModerate -
Server-Side XSS via JSX Escaping Bypass in cx() UtilityGHSA-w62v-xxxg-mg59 published
Jun 23, 2026 by yusukebeModerate -
CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcardGHSA-88fw-hqm2-52qc published
Jun 9, 2026 by yusukebeHigh -
hono/jsx does not isolate context per request, leading to cross-request data disclosureGHSA-hvrm-45r6-mjfj published
Jun 23, 2026 by yusukebeModerate -
Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`GHSA-rv63-4mwf-qqc2 published
Jun 9, 2026 by yusukebeModerate
Learn more about advisories related to honojs/hono in the GitHub Advisory Database