Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2026-39406 @hono/node-server: Middleware bypass via repeated slashes in serveStaticGHSA-frvp-7c67-39w9 Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)CVE-2026-13676 fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalizationCVE-2026-16221 Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ...CVE-2026-18446 fast-uri: fast-uri: Host confusion vulnerability via backslash in URI authorityCVE-2026-6321 fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policiesCVE-2026-6322 fast-uri: fast-uri: URI authority bypass due to improper delimiter handlingCVE-2026-54290 hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcardCVE-2026-39407 Hono: Middleware bypass via repeated slashes in serveStaticCVE-2026-39408 Hono: Path traversal in toSSG() allows writing files outside the output directoryCVE-2026-39409 Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addressesCVE-2026-39410 Hono: Non-breaking space prefix bypass in cookie name handling in getCookie()CVE-2026-44455 hono/jsx has Unvalidated JSX Tag Names that May Allow HTML InjectionCVE-2026-44456 Hono: bodyLimit() can be bypassed for chunked / unknown-length requestsCVE-2026-44457 Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakageCVE-2026-44458 Hono has CSS Declaration Injection via Style Object Values in JSX SSRCVE-2026-47673 Hono: JWT middleware accepts any Authorization scheme, not only BearerCVE-2026-47674 Hono: IP Restriction bypasses static deny rules for non-canonical IPv6 CVE-2026-47675 Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injectionCVE-2026-47676 Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded pathsCVE-2026-54286 hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)CVE-2026-54287 hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and LatticeCVE-2026-54288 hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`CVE-2026-54289 hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the restCVE-2026-56761 hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSRYour dependencies cross-checked against the OSV vulnerability database.
GHSA-92pp-h63x-v22m @hono/node-server: Middleware bypass via repeated slashes in serveStaticGHSA-frvp-7c67-39w9 Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)GHSA-4c8g-83qw-93j6 fast-uri vulnerable to host confusion via failed IDN canonicalizationGHSA-7p8r-x3mc-p8w7 fast-uri vulnerable to host confusion via backslash authority introducerGHSA-q3j6-qgpj-74h6 fast-uri vulnerable to path traversal via percent-encoded dot segmentsGHSA-v2hh-gcrm-f6hx fast-uri vulnerable to host confusion via literal backslash authority delimiterGHSA-v39h-62p7-jpjc fast-uri vulnerable to host confusion via percent-encoded authority delimitersGHSA-26pp-8wgv-hjvm Hono missing validation of cookie name on write path in setCookie()GHSA-2gcr-mfcq-wcc3 Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded pathsGHSA-3hrh-pfw6-9m5x Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injectionGHSA-458j-xx4x-4375 hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSRGHSA-54fx-42gc-7vw4 Hono: Algorithmic Complexity DoS in Language MiddlewareGHSA-69xw-7hcm-h432 hono/jsx has Unvalidated JSX Tag Names that May Allow HTML InjectionGHSA-88fw-hqm2-52qc hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcardGHSA-8j4g-w8fx-2239 Hono: ReDoS in CORS middleware via Access-Control-Request-HeadersGHSA-9vqf-7f2p-gf9v Hono: bodyLimit() can be bypassed for chunked / unknown-length requestsGHSA-f23p-vx2j-j53r Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosureGHSA-f577-qrjj-4474 Hono: JWT middleware accepts any Authorization scheme, not only BearerGHSA-hvrm-45r6-mjfj hono/jsx does not isolate context per request, leading to cross-request data disclosureGHSA-j6c9-x7qj-28xf hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and LatticeGHSA-p77w-8qqv-26rm Hono's Cache Middleware ignores Vary: Authorization / Vary: Cookie leading to cross-user cache leakageGHSA-qp7p-654g-cw7p Hono has CSS Declaration Injection via Style Object Values in JSX SSRGHSA-r5rp-j6wh-rvv4 Hono: Non-breaking space prefix bypass in cookie name handling in getCookie()GHSA-rv63-4mwf-qqc2 hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`GHSA-w62v-xxxg-mg59 Hono: Server-Side XSS via JSX Escaping Bypass in cx() UtilityCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.