Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-54288: CWE-345: Insufficient Verification of Data Authenticity in honojs honoCVE-2026-54288
0

Hono is a JavaScript web application framework with a vulnerability in its Body Limit Middleware prior to version 4.12.25. The middleware relies on the client-supplied Content-Length header to enforce request body size limits. On AWS Lambda environments, the actual request body may be larger than the declared Content-Length, allowing an attacker to bypass size restrictions by sending a smaller Content-Length value with a larger payload. This issue is fixed in version 4.12.25.

Join the discussion
CVE-2026-54290: CWE-942: Permissive Cross-domain Policy with Untrusted Domains in honojs honoCVE-2026-54290
0

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials: true and no explicit origin (the default wildcard), the CORS Middleware reflects the request's Origin and sends Access-Control-Allow-Credentials: true. Any site can then make credentialed cross-origin requests and read the responses, exposing cookie-authenticated endpoints to arbitrary origins. This vulnerability is fixed in 4.12.25.

Join the discussion
CVE-2026-54287: CWE-116: Improper Encoding or Escaping of Output in honojs honoCVE-2026-54287
0

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, the ALB single-header response and the VPC Lattice v2 response join multiple Set-Cookie headers into one comma-separated value. Because commas also appear inside cookie attributes (for example Expires dates), clients cannot split the value back into individual cookies and silently drop or misparse them. This vulnerability is fixed in 4.12.25.

Join the discussion
CVE-2026-54286: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in honojs honoCVE-2026-54286
0

Hono, a JavaScript web application framework, has a path traversal vulnerability (CWE-22) affecting versions prior to 4.12.25 on Windows hosts. An encoded backslash (%5C) in the request path is decoded to a backslash, which Windows treats as a path separator. This allows an attacker to access nested files outside intended directories, bypassing middleware protections. The vulnerability is fixed in version 4.12.25.

Join the discussion
CVE-2026-47676: CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in honojs honoCVE-2026-47676
0

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the incoming request path using the raw URL pathname, while route matching is performed against the percent-decoded path. This inconsistency causes the prefix to be stripped at the wrong position when the path contains percent-encoded multi-byte characters, resulting in the mounted sub-application receiving an incorrect path. This vulnerability is fixed in 4.12.21.

Join the discussion
CVE-2026-47675: CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') in honojs honoCVE-2026-47675
0

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path options against characters that corrupt Set-Cookie header syntax (;, \r, \n), but does not apply the same validation to sameSite and priority. An application that passes user-controlled input into either option may produce a Set-Cookie response header containing attacker-chosen additional attributes. This vulnerability is fixed in 4.12.21.

Join the discussion
CVE-2026-47674: CWE-185: Incorrect Regular Expression in honojs honoCVE-2026-47674
0

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restriction) compares incoming IP addresses against configured deny and allow rules using string equality after partial normalization. Non-canonical IPv6 representations of an address already listed in a static rule — such as compressed forms, explicit-zero forms, or hex-notation IPv4-mapped addresses — do not match the normalized rule entry, causing the rule to be silently skipped. This vulnerability is fixed in 4.12.21.

Join the discussion
CVE-2026-47673: CWE-285: Improper Authorization in honojs honoCVE-2026-47673
0

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify that the Authorization header value uses theBearer scheme. Any two-part header value — regardless of the scheme name in the first position — proceeds to JWT verification. A request presenting a valid JWT under a non-Bearer scheme identifier (such as Basic or Token) is authenticated identically to a correctly formed Bearer request. This vulnerability is fixed in 4.12.21.

Join the discussion

Showing 1 to 8 of 8 results

Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses