CVE-2026-29087 affects @hono/node-server versions prior to 1.19.10, allowing unauthorized access to protected static resources. This occurs due to inconsistent URL decoding between route-based middleware and static file resolution, specifically when encoded slashes (%2F) are present in the URL. Rated 7.5 HIGH (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), it poses a significant risk of information disclosure. There is no known active exploitation, public exploit code, or KEV listing, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.19.10CPE matchmatch criteria | cpe:2.3:a:hono:node-server:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.