Логотип exploitDog
bind:CVE-2026-24472
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-24472

Количество 2

Количество 2

nvd логотип

CVE-2026-24472

12 дней назад

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Cache Middleware contains an information disclosure vulnerability caused by improper handling of HTTP cache control directives. The middleware does not respect standard cache control headers such as `Cache-Control: private` or `Cache-Control: no-store`, which may result in private or authenticated responses being cached and subsequently exposed to unauthorized users. Version 4.11.7 has a patch for the issue.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-6wqw-2p9w-4vw4

12 дней назад

Hono cache middleware ignores "Cache-Control: private" leading to Web Cache Deception

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-24472

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Cache Middleware contains an information disclosure vulnerability caused by improper handling of HTTP cache control directives. The middleware does not respect standard cache control headers such as `Cache-Control: private` or `Cache-Control: no-store`, which may result in private or authenticated responses being cached and subsequently exposed to unauthorized users. Version 4.11.7 has a patch for the issue.

CVSS3: 5.3
0%
Низкий
12 дней назад
github логотип
GHSA-6wqw-2p9w-4vw4

Hono cache middleware ignores "Cache-Control: private" leading to Web Cache Deception

CVSS3: 5.3
0%
Низкий
12 дней назад

Уязвимостей на страницу