Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-62610

Опубликовано: 22 окт. 2025
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

Hono is a Web application framework that provides support for any JavaScript runtime. In versions from 1.1.0 to before 4.10.2, Hono’s JWT Auth Middleware does not provide a built-in aud (Audience) verification option, which can cause confused-deputy / token-mix-up issues: an API may accept a valid token that was issued for a different audience (e.g., another service) when multiple services share the same issuer/keys. This can lead to unintended cross-service access. Hono’s docs list verification options for iss/nbf/iat/exp only, with no aud support; RFC 7519 requires that when an aud claim is present, tokens MUST be rejected unless the processing party identifies itself in that claim. This issue has been patched in version 4.10.2.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hono:hono:*:*:*:*:*:node.js:*:*
Версия от 1.1.0 (включая) до 4.10.2 (исключая)

EPSS

Процентиль: 18%
0.00058
Низкий

8.1 High

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 8.1
github
4 месяца назад

Hono Improper Authorization vulnerability

EPSS

Процентиль: 18%
0.00058
Низкий

8.1 High

CVSS3

Дефекты

CWE-285