CVE-2026-29045Disclosure(hono / hono)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protections (e.g. app.use('/admin/*', ...)), inconsistent URL decoding allowed protected static resources to be accessed without authorization. The router used decodeURI, while serveStatic used decodeURIComponent. This mismatch allowed paths containing encoded slashes (%2F) to bypass middleware protections while still resolving to the intended filesystem path. This issue has been patched in version 4.12.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-177

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hono

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-04); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
hono

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-04: 2Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 103-0403-0503-06
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-042
Disclosure1General1
2026-03-051
General1
2026-03-061
Disclosure1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-29045 URL Decoding Bypass in Hono Framework Static Resource Access Control https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29045

    Post summary

    The post references CVE-2026-29045 and identifies a URL-decoding bypass in the Hono framework’s static resource access control, but provides no further technical details, PoC, exploit code, patch information, or evidence of active exploitation.

    0001031
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Hono (Framework), Auth Bypass, #CVE-2026-29045 (High) https://dailycve.com/hono-framework-auth-bypass-cve-2026-29045-high/

    Post summary

    This brief note announces a high‑severity authentication bypass flaw (CVE‑2026‑29045) affecting the Hono framework, linking to an external source for further details.

    0000034
    166 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-29045 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middle… https://www.cve.org/CVERecord?id=CVE-2026-29045 ----- Traducción: CVE-2026-29045 Hon… http://infoflow.cloud`

    Post summary

    Only the CVE ID and a minimal reference to a pre‑4.12.4 issue are provided, with a link to the CVE record; no details on exploitability, mitigation, or technical specifics are included.

    0000038
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29045 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middle… https://www.cve.org/CVERecord?id=CVE-2026-29045

    Post summary

    The text reports a vulnerability in Hono’s serveStatic functionality affecting versions before 4.12.4 but provides no exploitation or mitigation details.

    00000345
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphonohono-node.js-

Explore more