QSearchQSearch

CVE-2026-47676

5.3 MEDIUM

Hono is a Web application framework that provides support for any JavaScript runtime

Published: 2026-05-28 · Last updated: 2026-05-29

Severity and scoring

CVSS
5.3 MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE
CWE-444, CWE-693

Affected products

VendorProduct
honohono

Description

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the incoming request path using the raw URL pathname, while route matching is performed against the percent-decoded path. This inconsistency causes the prefix to be stripped at the wrong position when the path contains percent-encoded multi-byte characters, resulting in the mounted sub-application receiving an incorrect path. This vulnerability is fixed in 4.12.21.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-47675 Hono is a Web application framework that provides support for any JavaScript runtime (4.3 MEDIUM)
  • CVE-2026-47674 Hono is a Web application framework that provides support for any JavaScript runtime (5.3 MEDIUM)
  • CVE-2026-47673 Hono is a Web application framework that provides support for any JavaScript runtime (4.8 MEDIUM)

Same CWE

  • CVE-2026-50564 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes (9.9 CRITICAL)
  • CVE-2026-50545 Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes (9.9 CRITICAL)
  • CVE-2026-48575 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally (7.9 HIGH)
  • CVE-2026-48570 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally (7.9 HIGH)
  • CVE-2026-48568 Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally (7.9 HIGH)