Taku Amano
9 exploits
Active since Apr 2024
Hono <4.12.12 serveStatic - Middleware Bypass
CVSS 5.3
Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses
CVSS 5.3
Hono <4.12.12 getCookie() - Cookie Prefix Bypass
CVSS 4.8
Hono < 4.12.4 - Unauthenticated Path Traversal via URL-Encoded Slash Bypass
CVSS 7.5
Hono < 4.12.4 - Server-Sent Events Injection via Unvalidated Event Fields
CVSS 6.5
Hono < 4.12.4 - Cookie Attribute Injection via Set-Cookie Header
CVSS 5.4
hono/node-server 1.3.0-1.10.1 - Denial of Service via Malformed Host Header
CVSS 7.5
Hono < 4.11.7 - IP Address Validation Bypass via Malformed IPv4 Octet Handling
CVSS 4.8
Hono < 4.11.7 - Cross-Site Scripting in ErrorBoundary Component
CVSS 4.7