org.webjars.npm:hono

Licenses: MIT

Direct Vulnerabilities

Known vulnerabilities in the org.webjars.npm:hono package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Directory Traversal

[,4.12.25)
  • H
Use of a Broken or Risky Cryptographic Algorithm

[,4.11.4)
  • H
Improper Verification of Cryptographic Signature

[,4.11.4)
  • H
Permissive Cross-domain Policy with Untrusted Domains

[,4.12.25)
  • M
Incorrect Authorization

[,4.11.7)
  • M
Use of Cache Containing Sensitive Information

[,4.11.7)
  • M
Cross-site Scripting (XSS)

[,4.11.7)
  • M
Incorrect Regular Expression

[,4.11.7)
  • H
Unverified Ownership

[1.1.0,4.10.2)
  • H
Directory Traversal

[,4.13.5)
  • H
HTTP Request Smuggling

[,4.13.5)
  • M
Asymmetric Resource Consumption (Amplification)

[,4.13.5)
  • M
Arbitrary Code Injection

[,3.11.7)
  • M
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

[,4.2.7)
  • M
Improper Control of Generation of Code ('Code Injection')

[,3.11.7)
  • L
Cross-Site Request Forgery (CSRF)

[,4.5.8)
  • M
Cross-site Request Forgery (CSRF)

[,4.6.5)
  • H
Use of Incorrectly-Resolved Name or Reference

[4.8.0,4.9.6)
  • M
HTTP Request Smuggling

[,4.9.7)
  • H
Allocation of Resources Without Limits or Throttling

[,4.12.16)
  • H
Race Condition

[4.11.8,4.12.27)
  • M
Improperly Implemented Security Check for Standard

[,4.12.25)
  • M
Improper Encoding or Escaping of Output

[,4.12.25)
  • M
HTTP Response Splitting

[,4.12.12)
  • M
Cross-site Scripting (XSS)

[,4.12.14)
  • M
HTTP Request Smuggling

[,4.10.3)
  • M
Cross-site Scripting (XSS)

[4.0.0,4.12.27)
  • M
Use of Less Trusted Source

[4.3.3,4.12.27)
  • M
Prototype Pollution

[,4.12.7)
  • M
Timing Attack

[,4.11.10)
  • M
Regular Expression Denial of Service (ReDoS)

[,4.12.34)
  • M
Exposure of Data Element to Wrong Session

[3.8.0,4.12.34)
  • M
HTTP Request Smuggling

[4.7.0,4.12.34)
  • M
Inefficient Algorithmic Complexity

[4.12.0,4.12.34)
  • H
User Impersonation

[4.12.0,4.12.2)
  • M
CRLF Injection

[0.2.1,4.12.4)
  • M
CRLF Injection

[3.8.0,4.12.4)
  • M
Directory Traversal

[,4.12.12)
  • M
Improper Input Validation

[,4.12.12)
  • M
Directory Traversal

[4.0.0,4.12.12)
  • M
Incorrect Behavior Order: Validate Before Canonicalize

[,4.12.12)
  • M
Improper Handling of URL Encoding (Hex Encoding)

[,4.12.4)
  • M
Improper Encoding or Escaping of Output

[4.3.0,4.12.18)
  • M
Improper Validation of Specified Quantity in Input

[1.1.0,4.12.18)
  • M
Use of Cache Containing Sensitive Information

[2.0.3,4.12.18)
  • L
HTML Injection

[,4.12.16)
  • M
HTTP Request Smuggling

[,4.12.21)
  • M
Improper Authorization

[,4.12.21)
  • M
HTTP Response Splitting

[,4.12.21)
  • M
Incorrect Regular Expression

[,4.12.21)
  • M
Insufficient Verification of Data Authenticity

[,4.12.25)

Package versions

1 VERSIONS IN TOTAL
versionpublisheddirect vulnerabilities
4.13.128 Aug, 2026
  • 0
    C
  • 2
    H
  • 1
    M
  • 0
    L