Hono is a lightweight web framework for Node.js that has accumulated a meaningful volume of disclosures relative to its narrow product scope, placing it among more prominent frameworks in the vulnerability landscape. The vendor's disclosed vulnerabilities concentrate in path-traversal flaws, injection-class weaknesses, cross-site request forgery, improper authorization logic, and cryptographic-signature verification issues—weakness patterns typical of web application routing and request-handling layers that process untrusted input or manage session and authentication state. These recurring exposure vectors reflect the security surface inherent to a request-routing framework positioned between client requests and backend application logic. Defenders should treat Hono version updates as a routine patching concern for Node-based deployments that adopt this framework; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hono over time
Signals from CVEs in this vendor scope (42 CVEs).
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-29045CRITICAL Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protectio | Mar 4, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-59896MEDIUM Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/jsx did not isolate context values per request during server- | Jul 8, 2026 | 6.5 | 31 | NO | NO |
CVE-2026-39408HIGH Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows files to be written outside the con | Apr 8, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-59895MEDIUM Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks | Jul 8, 2026 | 6.1 | 29 | NO | NO |
CVE-2025-62610HIGH Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4.10.2, Hono’s JWT Auth Middleware does not provide a built-i | Oct 22, 2025 | 8.1 | 29 | NO | NO |
CVE-2026-59897MEDIUM Hono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS API Gateway v1 adapter can drop a distinct repeated request | Jul 8, 2026 | 5.3 | 28 | NO | NO |
CVE-2026-56763MEDIUM Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field names to create objects with __proto__ properties. When parsed | Jul 11, 2026 | 4.8 | 27 | NO | NO |
CVE-2025-71381MEDIUM Hono before 4.10.2 (fixed in 4.10.3) contains a flaw in its CORS middleware: when the origin is not set to "*", the middleware copies the Vary header from the incoming request into | Jun 30, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-29087HIGH @hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware | Mar 6, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-27700HIGH Hono is a Web application framework that provides support for any JavaScript runtime. In versions 4.12.0 and 4.12.1, when using the AWS Lambda adapter (`hono/aws-lambda`) behind an | Feb 25, 2026 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (42 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hono.
Media articles that mention a CVE ID that affects a product developed by Hono — matched by CVE ID, not by vendor name.