CVE-2026-56764: Hono

Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual function. Attackers can exploit early termination of string equality checks to infer valid credentials through precise timing measurements.

Affected products

  • Hono Hono: before 4.11.10 (fixed in 4.11.10)

Published 2026-07-15. Last modified 2026-07-15.