Yusuke Wada
13 exploits
Active since Dec 2023
Hono <4.12.12 toSSG() - Path Traversal
CVSS 7.5
Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses
CVSS 5.3
@hono/node-server <1.19.10 - Auth Bypass
CVSS 7.5
Hono < 3.11.7 - Path Parameter Override via TrieRouter
CVSS 4.2
hono/node-server 1.3.0-1.4.1 - Path Traversal via serveStatic
CVSS 5.3
Hono < 4.2.7 - Path Traversal via serveStatic in Deno
CVSS 5.3
Hono < 4.5.8 - Cross-Site Request Forgery Bypass via Crafted Content-Type Header
CVSS 5.0
Hono < 4.6.5 - CSRF Protection Bypass via Missing Content-Type Header
CVSS 5.9
Hono 4.8.0-4.9.5 - Path Confusion via Malformed Absolute-Form Request-URI
CVSS 7.5
Hono < 4.9.7 - Denial of Service via Body Size Limit Bypass
CVSS 5.3
Hono < 4.11.4 - JWT Algorithm Confusion via JWK/JWKS Middleware
CVSS 8.2
Hono < 4.11.7 - IP Address Validation Bypass via Malformed IPv4 Octet Handling
CVSS 4.8
Hono < 4.11.7 - Information Disclosure via Serve Static Middleware Path Validation
CVSS 5.3