hono is vulnerable to Authentication Bypass
53
Medium Risk
serveStatic decodes the routed request path a second time before resolving the file on disk. A request with a malformed percent encoded path segment matches the router while still partially encoded, then the second decode resolves to a different directory than the one the router matched. Middleware mounted on a static path prefix, including an authentication check, never runs for the file that actually gets served. The fix rejects routed paths containing a raw percent sign by default and adds an allowPercentInPath opt-in for the old behavior.
You are affected if you are using a version that falls within the vulnerable range and you mount middleware on a path prefix also served by serveStatic.
hono is vulnerable to Authentication Bypass in versions 4.12.4 - 4.13.10.
Upgrade the hono library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.