GHSA-wc8c-qw6v-h7f6
HIGHCVE-2026-29087When using @hono/node-server's static file serving together with route-based middleware protections (e.g. protecting /admin/), inconsistent URL decoding can allow protected static resources to be accessed without authorization.
- Affected
- < 1.19.10
- Fixed in
- 1.19.10
- Weakness
- CWE-863
- Published
- 2026-03-04
- Source
- github