Technology · npm
hono (npm) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 54 vulnerabilities in hono (npm): 0 in the last 7 days and 13 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-84365, was published on 1 September 2026.
- Last 7 days
- 0
- Last 90 days
- 13
- Critical, all time
- 0
- Exploited in the wild
- 0
About hono (npm)
A small, fast, web framework for Edges, such as Cloudflare Workers, Fastly Compute, and Deno.
Latest hono (npm) vulnerabilities
- CVE-2026-84365: Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix…mediumCVSS 6.5EPSS 0.4%
- CVE-2026-84364: Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, when parseBody()…mediumCVSS 5.3EPSS 0.5%
- CVE-2026-84363: Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, Hono's query…mediumCVSS 5.9EPSS 0.4%
- CVE-2026-71850: Hono hono/jsx cross-user data disclosure in memo functionmediumCVSS 4.8EPSS 0.3%
- CVE-2026-71849: Hono Proxy Helper information disclosure via hop-by-hop headerslowCVSS 3.7EPSS 0.4%
- CVE-2026-71848: Hono languageDetector algorithmic complexity DoSmediumCVSS 5.3EPSS 0.5%
- CVE-2026-69207: Hono ReDoS in CORS middleware via Access-Control-Request-HeadersmediumCVSS 5.3EPSS 0.6%
- CVE-2026-56764: Hono timing attack in basicAuth and bearerAuth middlewareslowCVSS 3.7EPSS 0.3%
- CVE-2026-56763: Hono prototype pollution in parseBody with dot option enabledmediumCVSS 4.8EPSS 0.3%
- CVE-2026-59897: Hono incorrect header de-duplication in AWS API Gateway adaptermediumCVSS 4.8EPSS 0.2%
- CVE-2026-59896: Hono race condition in JSX server-side rendering context isolationmediumCVSS 6.5EPSS 0.3%
- CVE-2026-59895: Hono XSS in hono/css cx() utilitymediumCVSS 6.1EPSS 0.3%
- CVE-2025-71381: Hono CORS middleware Vary header injectionmediumCVSS 6.5EPSS 0.3%
- CVE-2026-56761: Hono HTML injection in JSX server-side renderingmediumCVSS 4.3EPSS 0.3%
- Hono missing validation of cookie name in setCookie()lowCVSS 3.1
- Hono missing validation of cookie name in setCookie()mediumCVSS 5.3
- CVE-2026-56762: Hono missing cookie name validation in setCookiemediumCVSS 5.3EPSS 0.4%
- CVE-2026-54288: Hono Body Limit Middleware bypass on AWS LambdamediumCVSS 6.5EPSS 0.1%
- CVE-2026-54290: Hono permissive CORS policy in CORS MiddlewarehighCVSS 7.1EPSS 0.3%
- CVE-2026-54289: Hono header truncation in AWS Lambda@Edge adaptermediumCVSS 4.8EPSS 0.2%
- CVE-2026-54287: Hono improper cookie header merging in AWS Lambda adaptermediumCVSS 5.3EPSS 0.3%
- CVE-2026-54286: Hono path traversal in serve-static on WindowsmediumCVSS 5.9EPSS 0.4%
- CVE-2026-47676: Hono incorrect path stripping in app.mountmediumCVSS 5.3EPSS 0.3%
- CVE-2026-47675: Hono Set-Cookie injection in cookie serializationmediumCVSS 4.3EPSS 0.3%
- CVE-2026-47674: Hono ip-restriction middleware IP restriction bypass via non-canonical IPv6mediumCVSS 5.3EPSS 0.3%
Most severe hono (npm) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-39408: Hono path traversal in toSSG during static site generationhighCVSS 7.5EPSS 0.4%
- CVE-2026-54290: Hono permissive CORS policy in CORS MiddlewarehighCVSS 7.1EPSS 0.3%
- CVE-2026-84365: Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix…mediumCVSS 6.5EPSS 0.4%
- CVE-2026-59896: Hono race condition in JSX server-side rendering context isolationmediumCVSS 6.5EPSS 0.3%
- CVE-2025-71381: Hono CORS middleware Vary header injectionmediumCVSS 6.5EPSS 0.3%
- CVE-2026-44456: Hono bodyLimit bypass for chunked requestsmediumCVSS 6.5EPSS 0.3%
- CVE-2026-54288: Hono Body Limit Middleware bypass on AWS LambdamediumCVSS 6.5EPSS 0.1%
- CVE-2026-59895: Hono XSS in hono/css cx() utilitymediumCVSS 6.1EPSS 0.3%
- CVE-2026-84363: Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, Hono's query…mediumCVSS 5.9EPSS 0.4%
- CVE-2026-54286: Hono path traversal in serve-static on WindowsmediumCVSS 5.9EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 0 | |
| 6 Jul 2026 | 4 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 4 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 3 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/hono.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "hono (npm) vulnerabilities", https://junglewise.ai/threats/technologies/hono, 26 September 2026.