Skip to main content

Vendor/product archive

hono / node-server CVEs

Beta · best-effort

4 CVEs tagged to hono / node-server0 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-39406

Published Apr 8, 2026

@hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in serveStatic allows protected static files to be accessed by us…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-29087

Published Mar 6, 2026

@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-32652

Published Apr 19, 2024

The adapter @hono/node-server allows you to run your Hono application on Node.js. Prior to 1.10.1, the application hangs when receiving a Host header with a value that `@hono/node…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23340

Published Jan 22, 2024

@hono/node-server is an adapter that allows users to run Hono applications on Node.js. Since v1.3.0, @hono/node-server has used its own Request object with `url` behavior that is…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1