Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-constant-time string comparison in the timingSafeEqual function. Attackers can exploit early termination of string equality checks to infer valid credentials through precise timing measurements.
References
Configurations
No configuration.
History
15 Jul 2026, 12:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-15 12:18
Updated : 2026-07-15 21:02
NVD link : CVE-2026-56764
Mitre link : CVE-2026-56764
CVE.ORG link : CVE-2026-56764
JSON object : View
Products Affected
No product.
CWE
CWE-208
Observable Timing Discrepancy
