CVE-2024-43787: Hono
Medium severity, CVSS 5.0. EPSS: 0.2% chance of exploitation in the next 30 days.
Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypassed using crafted Content-Type header. MIME types are case insensitive, but isRequestedByFormElementRe only matches lower-case. As a result, attacker can bypass csrf middleware using upper-case form-like MIME type. This vulnerability is fixed in 4.5.8.
Affected products
- Hono Hono: before 4.5.8 (fixed in 4.5.8)
Published 2024-08-22. Last modified 2026-06-17.