Skip to content

fix: upgrade hono to 4.11.4 (CVE-2026-22817)#2458

Open
orbisai0security wants to merge 1 commit intoupstash:masterfrom
orbisai0security:fix-cve-2026-22817-hono
Open

fix: upgrade hono to 4.11.4 (CVE-2026-22817)#2458
orbisai0security wants to merge 1 commit intoupstash:masterfrom
orbisai0security:fix-cve-2026-22817-hono

Conversation

@orbisai0security
Copy link
Copy Markdown

Summary

Upgrade hono from 4.11.3 to 4.11.4 to fix CVE-2026-22817.

Vulnerability

Field Value
ID CVE-2026-22817
Severity HIGH
Scanner trivy
Rule CVE-2026-22817
File pnpm-lock.yaml

Description: Hono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass

Changes

  • package.json
  • pnpm-lock.yaml

Verification

  • Build passes
  • Scanner re-scan confirms fix
  • LLM code review passed

Automated security fix by OrbisAI Security

Automated dependency upgrade by Orbis Security AI
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant