hono is vulnerable to Sensitive Information Disclosure
53
Medium Risk
The cache middleware can cache responses that vary by Authorization or Cookie without skipping storage for per-user variants. A response generated for one authenticated user can then be reused for a different user under shared cache keys. This can expose user-specific data to unintended recipients. The fix treats Vary: Authorization and Vary: Cookie as cache-skip signals so user-scoped responses are not shared.
You are affected if you are using a version that falls within the vulnerable range.
hono is vulnerable to Sensitive Information Disclosure in versions 0.0.1 - 4.12.16.
Upgrade the hono library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant