4.12.25
4 years ago
8 days ago
Known vulnerabilities in the hono package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Permissive Cross-domain Policy with Untrusted Domains in the CORS middleware. An attacker can access sensitive information and perform unauthorized actions by sending cross-origin requests with credentials from arbitrary origins. This is only exploitable if the application enables credentials and leaves the origin unset or set to the wildcard. How to fix Permissive Cross-domain Policy with Untrusted Domains? Upgrade | <4.12.25 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output in the AWS Lambda adapter's handling of multiple How to fix Improper Encoding or Escaping of Output? Upgrade | <4.12.25 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? Upgrade | <4.12.25 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Improperly Implemented Security Check for Standard in the Lambda@Edge adapter that truncates repeated request headers. An attacker can bypass access restrictions or affect auditing mechanisms by sending repeated request headers, causing only the last value to be processed and earlier values to be ignored. How to fix Improperly Implemented Security Check for Standard? Upgrade | <4.12.25 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Insufficient Verification of Data Authenticity in the Body Limit Middleware. An attacker can cause the application to process payloads larger than the configured maximum by understating the How to fix Insufficient Verification of Data Authenticity? Upgrade | <4.12.25 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Incorrect Regular Expression via the How to fix Incorrect Regular Expression? Upgrade | <4.12.21 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to HTTP Response Splitting via the How to fix HTTP Response Splitting? Upgrade | <4.12.21 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Improper Authorization via the How to fix Improper Authorization? Upgrade | <4.12.21 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to HTTP Request Smuggling via the How to fix HTTP Request Smuggling? Upgrade | <4.12.21 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Use of Cache Containing Sensitive Information through the Workarounds
How to fix Use of Cache Containing Sensitive Information? Upgrade | >=2.0.3 <4.12.18 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Improper Validation of Specified Quantity in Input through the Note: This is only exploitable if the attacker can issue tokens accepted by the application or has control over the signing key. How to fix Improper Validation of Specified Quantity in Input? Upgrade | >=1.1.0 <4.12.18 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to HTML Injection via the Note: This is only exploitable if applications construct JSX tag names from untrusted input; applications using static or allowlisted tag names are not affected. How to fix HTML Injection? Upgrade | <4.12.16 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the How to fix Allocation of Resources Without Limits or Throttling? Upgrade | <4.12.16 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? Upgrade | <4.12.14 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Incorrect Behavior Order: Validate Before Canonicalize in the How to fix Incorrect Behavior Order: Validate Before Canonicalize? Upgrade | <4.12.12 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Directory Traversal in the Note: This is only exploitable if an attacker can influence the values passed to How to fix Directory Traversal? Upgrade | >=4.0.0 <4.12.12 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Improper Input Validation via the How to fix Improper Input Validation? Upgrade | <4.12.12 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to HTTP Response Splitting via the How to fix HTTP Response Splitting? Upgrade | <4.12.12 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? Upgrade | <4.12.12 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Prototype Pollution in How to fix Prototype Pollution? Upgrade | <4.12.7 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to CRLF Injection via the How to fix CRLF Injection? Upgrade | >=3.8.0 <4.12.4 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Improper Handling of URL Encoding (Hex Encoding) via inconsistent URL decoding between the Note: This vulnerability specifically affects applications that rely solely on route-based middleware to protect static subpaths. How to fix Improper Handling of URL Encoding (Hex Encoding)? Upgrade | <4.12.4 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to CRLF Injection via the Notes:
How to fix CRLF Injection? Upgrade | >=0.2.1 <4.12.4 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Timing Attack via the How to fix Timing Attack? Upgrade | <4.11.10 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Use of Cache Containing Sensitive Information via improper handling of HTTP cache control directives, including How to fix Use of Cache Containing Sensitive Information? Upgrade | <4.11.7 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Incorrect Authorization via improper validation of user-supplied paths in the How to fix Incorrect Authorization? Upgrade | <4.11.7 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? Upgrade | <4.11.7 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Incorrect Regular Expression in the form of the How to fix Incorrect Regular Expression? Upgrade | <4.11.7 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Use of a Broken or Risky Cryptographic Algorithm due to the JWT verification middleware using unsafe default fallback algorithm. An attacker can gain unauthorized access or escalate privileges by crafting JWTs with manipulated Note: Users that configured their app without JWK/JWKS middleware or explicitly restrict allowed algorithms are not affected. How to fix Use of a Broken or Risky Cryptographic Algorithm? Upgrade | <4.11.4 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature due to the JWT verification middleware fallback on unverified JWT header when Note: Users that configured their app without JWK/JWKS middleware or explicitly restrict allowed algorithms are not affected. How to fix Improper Verification of Cryptographic Signature? Upgrade | <4.11.4 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to HTTP Request Smuggling via the CORS middleware, which copies the Note:
This is exploitable if shared caches or proxies rely on the How to fix HTTP Request Smuggling? Upgrade | <4.10.3 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Unverified Ownership via the JWT authentication process. An attacker can gain unauthorized access to protected resources by presenting a valid token intended for a different audience when multiple services share the same issuer or keys. How to fix Unverified Ownership? Upgrade | >=1.1.0 <4.10.2 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to HTTP Request Smuggling via the Note:
This is exploitable if the deployment environment or runtime does not reject requests with both How to fix HTTP Request Smuggling? Upgrade | <4.9.7 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) through the How to fix Cross-site Request Forgery (CSRF)? Upgrade | <4.6.5 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Cross-Site Request Forgery (CSRF) via the How to fix Cross-Site Request Forgery (CSRF)? Upgrade | <4.5.8 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') such that when using How to fix Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')? Upgrade | <4.2.7 |