Executive brief
Hono is a popular web framework used to build APIs and backend services. Its JWT authentication middleware fails to validate the audience (aud) claim by default, allowing tokens issued for one service to be accepted by another service that shares the same signing keys. In a multi-service environment using a shared identity provider, an attacker can obtain a valid token for a different service and use it to access restricted endpoints, bypassing authorization controls.
Technical details
The vulnerability is an improper authorization issue (CWE-285) stemming from missing JWT audience (aud) claim validation in Hono's JWT middleware. The middleware's verifyOptions enumerate iss, nbf, iat, and exp claims but lack aud support, violating RFC 7519 §4.1.3 which requires tokens to be rejected if the aud claim does not match the intended recipient. Attack vector is network-based with no privileges required but requires user interaction (e.g., a victim logging in via a shared OAuth provider). An attacker can obtain a valid token intended for Service B and use it to access Service A if both share signing keys. The vulnerability affects versions from 1.1.0 through 4.10.1; it was patched in version 4.10.2 by adding a verification.aud configuration option.
Affected products
- Hono Hono 1.1.0 through 4.10.1
Timeline
- 2025-10-22: disclosed: GHSA advisory published
- 2025-10-22: patched: Fixed in version 4.10.2 with verification.aud option