CVE Tools

Honojs

15 CVEs tracked since 2026. Since Jan 2026, none of them reached CISA KEV.

Honojs CVEs per month

Jan 2026 to May 2026. Point at a month, or focus the strip and use the arrow keys.
Honojs CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-0160
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-0590

Products

The products that kept showing up in Honojs's monthly top three, with their CVEs summed over those months.

  1. Hono152 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Honojs.

  1. CVE-2026-93981hono/jsx before 4.13.7 Cross-Site Scripting via Unescaped Strings4.7
  2. CVE-2026-84365Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory6.5
  3. CVE-2026-84364Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion5.3
  4. CVE-2026-84363Hono: Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials5.9
  5. CVE-2026-81888@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking5.4
  6. CVE-2026-73565@hono/node-server: Unauthenticated memory-leak DoS via aborted WebSocket handshake5.3
  7. CVE-2026-69207Hono: ReDoS in CORS middleware via Access-Control-Request-Headers5.3
  8. CVE-2026-71850Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure4.8
  9. CVE-2026-71849Hono: Proxy Helper does not remove response headers listed in the `Connection` header3.7
  10. CVE-2026-71848Hono: Algorithmic Complexity DoS in Language Middleware5.3
  11. CVE-2026-59895Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility6.1
  12. CVE-2026-59896hono/jsx does not isolate context per request, leading to cross-request data disclosure6.5
  13. CVE-2026-59897Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication4.8
  14. CVE-2026-54288Hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`6.5
  15. CVE-2026-54289Hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest4.8

The record

Peak rank
#147 in May 2026
Busiest month shown
May 2026, 9 CVEs
Months with a KEV entry
0 since Jan 2026
Monthly snapshots
2 since 2026
Honojs's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store