hono is vulnerable to Improper Input Validation
38
Low Risk
JWT verification accepts malformed NumericDate claims for exp, nbf, and iat in some non-compliant value forms. Falsy, non-finite, or non-numeric values can bypass intended time-based checks instead of being rejected. This weakens token lifetime and not-before validation when malformed claims are introduced. The fix enforces strict NumericDate validation and rejects invalid claim types and values during verify-time checks.
You are affected if you are using a version that falls within the vulnerable range.
hono is vulnerable to Improper Input Validation in versions 0.0.1 - 4.12.16.
Upgrade the hono library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant