CVE-2026-22818Patch(hono / hono)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch hono hono systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the algorithm specified in the JWT header to influence signature verification when the selected JWK did not explicitly define an algorithm. This could enable JWT algorithm confusion and, in certain configurations, allow forged tokens to be accepted. The JWK/JWKS JWT verification middleware has been updated to require an explicit allowlist of asymmetric algorithms when verifying tokens. The middleware no longer derives the verification algorithm from untrusted JWT header values. This vulnerability is fixed in 4.11.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hono

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-27); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
hono

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-27: 1Mentions · 2026-07-02: 1Patch / Workaround · 2026-06-27: 1Technical Details · 2026-06-27: 106-2707-02
Signal classification2 categories
Patch
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-06-271
Patch1
2026-07-021
General1
Full discourse2 posts
  • かろっく@calloc134
    Patch

    ちなみに今なので言える話だが、自分が修正した CVE-2026-22818 悪用しようとするとWebCrypto の importKey()でRSA形式のJWKをHMAC鍵でないと判定してエラーを返すので、悪用は不可能だったりする 塞いでおいた方が良いことには代わりないけど https://zenn.dev/calloc134/articles/hono-jwt-jwk-alg-confusion

    Post summary

    The post discusses CVE‑2026‑22818, a JWK algorithm confusion in WebCrypto importKey; the author fixed it, notes that exploitation is blocked by an import error, and links to an article detailing the fix.

    0201971.5K
    4.1K followersView on X
  • てらら👯@a_terarara
    General

    用法理解をより深く理解し、より優れた解決策を選べるのか。 実例から学ぶ。 => Hono JWK Middleware - CVE-2026-22818 #ID沼入口

    Post summary

    The short Japanese text only mentions the CVE-2026-22818 identifier without providing any additional technical or operational details.

    00020286
    482 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphonohono-node.js-

Explore more