OSS Support Hub / Web Framework

Node.js Web Framework MIT Latest: v4.12.27

Hono

Ultrafast, lightweight web framework for the Edges — runs on Cloudflare Workers, Deno, Bun, and Node.js

Project Health at a Glance

Live data from GitHub and npm, updated daily.

31.2K+464
GitHub Stars
📦
v4.12.27
Latest Release · 6 days ago
🔄
5d
Avg. Release Cadence
🐛
370
Open Issues
📅
6 days ago
Last Commit
⬇️
47.6M
Weekly Downloads
🔒
10
Active CVEs

Data last fetched: 2026-06-29

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Hono allows bypass of CSRF Middleware by a request without Content-Type header.

Published: 2024-10-15 Fixed in: 4.6.5

Hono missing validation of cookie name on write path in setCookie()

Published: 2026-04-08 Fixed in: 4.12.12

Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths

Published: 2026-06-04 Fixed in: 4.12.21

Hono: Cookie helper does not sanitize sameSite and priority, allowing Set-Cookie injection

Published: 2026-06-04 Fixed in: 4.12.21

Hono vulnerable to Restricted Directory Traversal in serveStatic with deno

Published: 2024-04-23 Fixed in: 4.2.7

Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback)

Published: 2026-01-13 Fixed in: 4.11.4

hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR

Published: 2026-04-16 Fixed in: 4.12.14

Hono Vulnerable to Cookie Attribute Injection via Unsanitized domain and path in setCookie()

Published: 2026-03-04 Fixed in: 4.12.4

hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection

Published: 2026-05-06 Fixed in: 4.12.16

Hono cache middleware ignores "Cache-Control: private" leading to Web Cache Deception

Published: 2026-01-27 Fixed in: 4.11.7

Alternatives to Hono

Other Web Framework projects in the Node.js ecosystem worth evaluating.

Support Options for Hono

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Hono — without relying on volunteer maintainers.