Junglewise Threat Intelligence

CVE-2026-47673: Hono improper authorization in JWT and JWK middleware

CVE-2026-47673 · Severity: medium · CVSS 4.8 · Published 2026-05-28

Technologies: Honojs Hono. Vendors: npm.

Executive brief

Hono is a web framework used to build APIs and web applications. A vulnerability in its authentication middleware allows attackers to bypass certain network security filters, such as Web Application Firewalls (WAFs), by using non-standard authorization headers. While the attacker still needs a valid security token, this flaw allows them to circumvent protections designed to monitor or block specific types of login traffic.

Technical details

The 'jwt' and 'jwk' middlewares in Hono split the 'Authorization' header value by whitespace and verify the second part as a JWT without validating that the first part (the scheme) is 'Bearer'. This violates RFC 6750 and allows an attacker with a valid JWT to use alternative scheme identifiers like 'Basic' or 'Token'. This behavior can be used to bypass network-layer security controls (WAFs, API gateways, or reverse proxies) that are configured to inspect or filter traffic specifically based on the 'Bearer' scheme identifier. The issue is fixed in version 4.12.21.

Affected products

  • honojs hono < 4.12.21

Timeline

  • 2026-05-19: disclosed: Initial disclosure by reporter SQU4NCH
  • 2026-05-28: advisory: NVD publication date
  • 2026-06-04: patched: GitHub Advisory published and version 4.12.21 released

References

Related threats