VendorsHononode-serverany version
Vulnerabilities

Hono Node-server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2024-32652
@hono/node-server contains Denial of Service risk when receiving Host header that cannot be parsed
Published 2024-04-19 · Analyzed
7.5EPSS 0.009
CVE-2026-29087
@hono/node-server: Authorization bypass for protected static paths via encoded slashes in Serve Static Middleware
Published 2026-03-06 · Analyzed
7.5EPSS 0.004
CVE-2024-23340
@hono/node-server can't handle "double dots" in URL
Published 2024-01-22 · Modified
5.3EPSS 0.007
CVE-2026-39406
@hono/node-server has a middleware bypass via repeated slashes in serveStatic
Published 2026-04-08 · Analyzed
5.3EPSS 0.004