OSS Support Hub / Web Framework

Node.js Web Framework MIT Latest: v4.12.18

Hono

Ultrafast, lightweight web framework for the Edges — runs on Cloudflare Workers, Deno, Bun, and Node.js

Project Health at a Glance

Live data from GitHub and npm, updated daily.

30.5K
GitHub Stars
📦
v4.12.18
Latest Release · 9 days ago
🔄
5d
Avg. Release Cadence
🐛
369
Open Issues
📅
2 days ago
Last Commit
⬇️
33.7M
Weekly Downloads
🔒
10
Active CVEs

Data last fetched: 2026-05-15

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Hono allows bypass of CSRF Middleware by a request without Content-Type header.

Published: 2024-10-15 Fixed in: 4.6.5

Hono missing validation of cookie name on write path in setCookie()

Published: 2026-04-08 Fixed in: 4.12.12

Hono vulnerable to Restricted Directory Traversal in serveStatic with deno

Published: 2024-04-23 Fixed in: 4.2.7

Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback)

Published: 2026-01-13 Fixed in: 4.11.4

hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR

Published: 2026-04-16 Fixed in: 4.12.14

Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie()

Published: 2026-03-04 Fixed in: 4.12.4

hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection

Published: 2026-05-06 Fixed in: 4.12.16

Hono cache middleware ignores "Cache-Control: private" leading to Web Cache Deception

Published: 2026-01-27 Fixed in: 4.11.7

Hono has Body Limit Middleware Bypass

Published: 2025-09-12 Fixed in: 4.9.7

Hono's flaw in URL path parsing could cause path confusion

Published: 2025-09-03 Fixed in: 4.9.6

Alternatives to Hono

Other Web Framework projects in the Node.js ecosystem worth evaluating.

Support Options for Hono

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Hono — without relying on volunteer maintainers.

Talk to an Expert →