4.12.8
4 years ago
13 hours ago
Known vulnerabilities in the hono package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Prototype Pollution in How to fix Prototype Pollution? Upgrade | <4.12.7 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to CRLF Injection via the How to fix CRLF Injection? Upgrade | >=3.8.0 <4.12.4 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to Improper Handling of URL Encoding (Hex Encoding) via inconsistent URL decoding between the Note: This vulnerability specifically affects applications that rely solely on route-based middleware to protect static subpaths. How to fix Improper Handling of URL Encoding (Hex Encoding)? Upgrade | <4.12.4 |
hono is an Ultrafast web framework for the Edges Affected versions of this package are vulnerable to CRLF Injection via the Notes:
How to fix CRLF Injection? Upgrade | >=0.2.1 <4.12.4 |