Package impact

npm npm / @hono/node-server

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-39406 unknown 2mo ago @hono/node-server: Middleware bypass via repeated slashes in serveStatic
CVE-2026-29087 unknown 3mo ago @hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware
CVE-2024-32652 unknown 2y ago @hono/node-server has Denial of Service risk when receiving Host header that cannot be parsed
CVE-2024-23340 unknown 2y ago @hono/node-server cannot handle "double dots" in URL