Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-54288: CWE-345: Insufficient Verification of Data Authenticity in honojs honoCVE-2026-54288 0 Hono is a JavaScript web application framework with a vulnerability in its Body Limit Middleware prior to version 4.12.25. The middleware relies on the client-supplied Content-Length header to enforce request body size limits. On AWS Lambda environments, the actual request body may be larger than the declared Content-Length, allowing an attacker to bypass size restrictions by sending a smaller Content-Length value with a larger payload. This issue is fixed in version 4.12.25. Join the discussion | CVE Database V5 | 06/22/2026, 17:18:24 UTC Added: 06/22/2026, 19:09:21 UTC |
CVE-2026-54290: CWE-942: Permissive Cross-domain Policy with Untrusted Domains in honojs honoCVE-2026-54290 0 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials: true and no explicit origin (the default wildcard), the CORS Middleware reflects the request's Origin and sends Access-Control-Allow-Credentials: true. Any site can then make credentialed cross-origin requests and read the responses, exposing cookie-authenticated endpoints to arbitrary origins. This vulnerability is fixed in 4.12.25. Join the discussion | CVE Database V5 | 06/22/2026, 17:15:35 UTC Added: 06/22/2026, 17:39:40 UTC |
CVE-2026-54287: CWE-116: Improper Encoding or Escaping of Output in honojs honoCVE-2026-54287 0 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, the ALB single-header response and the VPC Lattice v2 response join multiple Set-Cookie headers into one comma-separated value. Because commas also appear inside cookie attributes (for example Expires dates), clients cannot split the value back into individual cookies and silently drop or misparse them. This vulnerability is fixed in 4.12.25. Join the discussion | CVE Database V5 | 06/22/2026, 17:13:14 UTC Added: 06/22/2026, 17:39:40 UTC |
CVE-2026-54286: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in honojs honoCVE-2026-54286 0 Hono, a JavaScript web application framework, has a path traversal vulnerability (CWE-22) affecting versions prior to 4.12.25 on Windows hosts. An encoded backslash (%5C) in the request path is decoded to a backslash, which Windows treats as a path separator. This allows an attacker to access nested files outside intended directories, bypassing middleware protections. The vulnerability is fixed in version 4.12.25. Join the discussion | CVE Database V5 | 06/22/2026, 17:14:40 UTC Added: 06/22/2026, 17:39:40 UTC |
CVE-2026-47676: CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in honojs honoCVE-2026-47676 0 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() strips the mount prefix from the incoming request path using the raw URL pathname, while route matching is performed against the percent-decoded path. This inconsistency causes the prefix to be stripped at the wrong position when the path contains percent-encoded multi-byte characters, resulting in the mounted sub-application receiving an incorrect path. This vulnerability is fixed in 4.12.21. Join the discussion | CVE Database V5 | 05/28/2026, 15:26:01 UTC Added: 05/28/2026, 16:48:48 UTC |
CVE-2026-47675: CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') in honojs honoCVE-2026-47675 0 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() function in hono/cookie validates domain and path options against characters that corrupt Set-Cookie header syntax (;, \r, \n), but does not apply the same validation to sameSite and priority. An application that passes user-controlled input into either option may produce a Set-Cookie response header containing attacker-chosen additional attributes. This vulnerability is fixed in 4.12.21. Join the discussion | CVE Database V5 | 05/28/2026, 15:28:23 UTC Added: 05/28/2026, 16:48:44 UTC |
CVE-2026-47674: CWE-185: Incorrect Regular Expression in honojs honoCVE-2026-47674 0 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restriction middleware (hono/ip-restriction) compares incoming IP addresses against configured deny and allow rules using string equality after partial normalization. Non-canonical IPv6 representations of an address already listed in a static rule — such as compressed forms, explicit-zero forms, or hex-notation IPv4-mapped addresses — do not match the normalized rule entry, causing the rule to be silently skipped. This vulnerability is fixed in 4.12.21. Join the discussion | CVE Database V5 | 05/28/2026, 15:29:08 UTC Added: 05/28/2026, 16:48:44 UTC |
CVE-2026-47673: CWE-285: Improper Authorization in honojs honoCVE-2026-47673 0 Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk middlewares do not verify that the Authorization header value uses theBearer scheme. Any two-part header value — regardless of the scheme name in the first position — proceeds to JWT verification. A request presenting a valid JWT under a non-Bearer scheme identifier (such as Basic or Token) is authenticated identically to a correctly formed Bearer request. This vulnerability is fixed in 4.12.21. Join the discussion | CVE Database V5 | 05/28/2026, 15:29:44 UTC Added: 05/28/2026, 16:48:44 UTC |
Showing 1 to 8 of 8 results