Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2898 | Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by a request without Content-Type header. Although the CSRF middleware verifies the Content-Type Header, Hono always considers a request without a Content-Type header to be safe. This can allow an attacker to bypass CSRF protection implemented with Hono CSRF middleware. Version 4.6.5 fixes this issue. |
Github GHSA |
GHSA-2234-fmw7-43wr | Hono allows bypass of CSRF Middleware by a request without Content-Type header. |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 07 Nov 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Honor vulnerable to bypass of CSRF Middleware by a request without Content-Type header. | Hono vulnerable to bypass of CSRF Middleware by a request without Content-Type header. |
Tue, 15 Oct 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hono
Hono hono |
|
| CPEs | cpe:2.3:a:hono:hono:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Hono
Hono hono |
|
| Metrics |
ssvc
|
Tue, 15 Oct 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by a request without Content-Type header. Although the CSRF middleware verifies the Content-Type Header, Hono always considers a request without a Content-Type header to be safe. This can allow an attacker to bypass CSRF protection implemented with Hono CSRF middleware. Version 4.6.5 fixes this issue. | |
| Title | Honor vulnerable to bypass of CSRF Middleware by a request without Content-Type header. | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-11-07T18:33:39.270Z
Reserved: 2024-10-09T22:06:46.171Z
Link: CVE-2024-48913
Updated: 2024-10-15T16:15:37.945Z
Status : Analyzed
Published: 2024-10-15T16:15:05.960
Modified: 2025-09-17T20:35:07.983
Link: CVE-2024-48913
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA