Security: honojs/hono
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injectionGHSA-3hrh-pfw6-9m5x published
May 19, 2026 by yusukebeModerate -
JWT middleware accepts any Authorization scheme, not only BearerGHSA-f577-qrjj-4474 published
May 19, 2026 by yusukebeModerate -
Improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()GHSA-hm8q-7f3q-5f36 published
May 6, 2026 by yusukebeLow -
bodyLimit() can be bypassed for chunked / unknown-length requestsGHSA-9vqf-7f2p-gf9v published
Apr 30, 2026 by yusukebeModerate -
CSS Declaration Injection via Style Object Values in JSX SSRGHSA-qp7p-654g-cw7p published
May 6, 2026 by yusukebeModerate -
Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakageGHSA-p77w-8qqv-26rm published
May 6, 2026 by yusukebeModerate -
Unvalidated JSX Tag Names in hono/jsx May Allow HTML InjectionGHSA-69xw-7hcm-h432 published
Apr 30, 2026 by yusukebeModerate -
Improper Handling of JSX Attribute Names Allows HTML Injection in hono/jsx SSRGHSA-458j-xx4x-4375 published
Apr 15, 2026 by yusukebeModerate -
Non-breaking space prefix bypass in cookie name handling in getCookie()GHSA-r5rp-j6wh-rvv4 published
Apr 7, 2026 by yusukebeModerate -
Missing validation of cookie name on write path in setCookie()GHSA-26pp-8wgv-hjvm published
Apr 7, 2026 by yusukebeModerate
Learn more about advisories related to honojs/hono in the GitHub Advisory Database