CVE-2026-22817Disclosure(hono / hono)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the JWT header’s alg value to influence signature verification when the selected JWK did not explicitly specify an algorithm. This could enable JWT algorithm confusion and, in certain configurations, allow forged tokens to be accepted. As part of this fix, the JWT middleware now requires the alg option to be explicitly specified. This prevents algorithm confusion by ensuring that the verification algorithm is not derived from untrusted JWT header values. This vulnerability is fixed in 4.11.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hono

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
hono

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-17: 108-17
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Tao Idr@tao_idr
    Disclosure

    Critical CVEs affect JWT libraries into 2026, including CVE-2026-22817. Researchers logged 6 critical JWT CVEs in 2025 alone, with one bug bounty paying $10k for a single forged admin token.

    Post summary

    A new critical CVE, CVE-2026-22817, is announced for JWT libraries, with mention of a 2025 bug bounty for forging an admin token.

    1000032
    156 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphonohono-node.js-

Explore more