Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6 advisories

Loading
Hono Vulnerable to SSE Control Field Injection via CR/LF in writeSSE() Moderate
CVE-2026-29085 was published for hono (npm) Mar 4, 2026
TarPeg007 Credited to TarPeg007
Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie() Moderate
CVE-2026-29086 was published for hono (npm) Mar 4, 2026
TarPeg007 Credited to TarPeg007
Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation Moderate
CVE-2026-3419 was published for fastify (npm) Mar 5, 2026
TarPeg007 Credited to TarPeg007, jsumners, mcollina, and UlisesGascon jsumners jsumners
mcollina mcollina UlisesGascon UlisesGascon
hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection Moderate
CVE-2026-44455 was published for hono (npm) May 6, 2026
TarPeg007 Credited to TarPeg007
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake Moderate
CVE-2026-73565 was published for @hono/node-server (npm) Jul 21, 2026
TarPeg007 Credited to TarPeg007
@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking Moderate
CVE-2026-81888 was published for @hono/oauth-providers (npm) Aug 31, 2026
TarPeg007 Credited to TarPeg007
ProTip! Advisories are also available from the GraphQL API