CVE-2024-48913

MEDIUM

Hono < 4.6.5 - CSRF Protection Bypass via Missing Content-Type Header

Title source: llm
STIX 2.1

Description

Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by a request without Content-Type header. Although the CSRF middleware verifies the Content-Type Header, Hono always considers a request without a Content-Type header to be safe. This can allow an attacker to bypass CSRF protection implemented with Hono CSRF middleware. Version 4.6.5 fixes this issue.

Scores

CVSS v3 5.9
EPSS 0.0030
EPSS Percentile 21.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (2)
hono/hono < 4.6.5
npm/hono 0 - 4.6.5npm
Published Oct 15, 2024
Tracked Since Feb 18, 2026