CVE-2026-56764: Hono
Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.
Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual function. Attackers can exploit early termination of string equality checks to infer valid credentials through precise timing measurements.
Affected products
- Hono Hono: before 4.11.10 (fixed in 4.11.10)
Published 2026-07-15. Last modified 2026-07-15.