{
  "@id": "urn:uuid:e8e2cba5-d820-459f-9863-6e0790da77d8",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 11,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-10-03T10:13:00.652366+00:00",
  "statements": [
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-28T11:46:34.644596+00:00",
      "status_notes": "Vulnerability CVE-2024-32869 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2024-32869"
      },
      "action_statement": "Vulnerability CVE-2024-32869 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-26T08:59:00.197456+00:00",
      "status_notes": "Vulnerability CVE-2024-43787 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2024-43787"
      },
      "action_statement": "Vulnerability CVE-2024-43787 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-28T11:46:34.644596+00:00",
      "status_notes": "Vulnerability CVE-2024-48913 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2024-48913"
      },
      "action_statement": "Vulnerability CVE-2024-48913 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-24T15:17:19.590664+00:00",
      "status_notes": "Vulnerability CVE-2025-59139 does not affect version 3.12.12 of hono. not_affected \u2014 Hono version 3.12.12 is not affected by CVE-2025-59139. The vulnerable component (bodyLimit middleware) does not exist in this version. The middleware was introduced later in version 4.0.6 (commit 466bf491, March 2024), making it impossible for the header prioritization vulnerability to manifest in version 3.12.12.",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2025-59139"
      },
      "impact_statement": "not_affected \u2014 Hono version 3.12.12 is not affected by CVE-2025-59139. The vulnerable component (bodyLimit middleware) does not exist in this version. The middleware was introduced later in version 4.0.6 (commit 466bf491, March 2024), making it impossible for the header prioritization vulnerability to manifest in version 3.12.12."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-28T11:46:34.644596+00:00",
      "status_notes": "Vulnerability CVE-2025-62610 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2025-62610"
      },
      "action_statement": "Vulnerability CVE-2025-62610 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-10-02T18:46:00.343734+00:00",
      "status_notes": "Vulnerability CVE-2025-71381 does not affect version 3.12.12 of hono. not_affected \u2014 Version 3.12.12 does not contain CVE-2025-71381. The vulnerability (CORS middleware reflecting attacker-controlled Vary headers from requests into responses) was introduced in commit 1a32ef4d on June 9, 2024, four months AFTER v3.12.12 was released on February 8, 2024. The target version predates the vulnerable code and never included it in its lineage.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-71381"
      },
      "impact_statement": "not_affected \u2014 Version 3.12.12 does not contain CVE-2025-71381. The vulnerability (CORS middleware reflecting attacker-controlled Vary headers from requests into responses) was introduced in commit 1a32ef4d on June 9, 2024, four months AFTER v3.12.12 was released on February 8, 2024. The target version predates the vulnerable code and never included it in its lineage."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-28T11:46:34.644596+00:00",
      "status_notes": "Vulnerability CVE-2026-22817 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-22817"
      },
      "action_statement": "Vulnerability CVE-2026-22817 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-10-03T10:13:00.652366+00:00",
      "status_notes": "Vulnerability CVE-2026-22818 does not affect version 3.12.12 of hono. Version 3.12.12 is not affected by CVE-2026-22818 because the vulnerable JWK/JWKS authentication middleware does not exist in this version. The JWK middleware was added to Hono on 2025-02-06 (in the v4.6.x series), almost exactly one year after v3.12.12 was released on 2024-02-08. The vulnerability and its fix (v4.11.4) are specific to the v4.x series. This version only contains basic JWT middleware using symmetric HMAC algorithms with shared secrets, not the public key-based JWK/JWKS verification that is vulnerable to the algorithm confusion attack.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-22818"
      },
      "impact_statement": "Version 3.12.12 is not affected by CVE-2026-22818 because the vulnerable JWK/JWKS authentication middleware does not exist in this version. The JWK middleware was added to Hono on 2025-02-06 (in the v4.6.x series), almost exactly one year after v3.12.12 was released on 2024-02-08. The vulnerability and its fix (v4.11.4) are specific to the v4.x series. This version only contains basic JWT middleware using symmetric HMAC algorithms with shared secrets, not the public key-based JWK/JWKS verification that is vulnerable to the algorithm confusion attack."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-24T15:17:19.590664+00:00",
      "status_notes": "Vulnerability CVE-2026-24398 does not affect version 3.12.12 of hono. not_affected \u2014 The target repository (Hono version 3.12.12) is not affected by CVE-2026-24398. The vulnerable IP Restriction Middleware feature and its associated IPv4 validation code in `src/utils/ipaddr.ts` do not exist in this version. The feature was introduced in version 4.x (commit 71cdcf40) and subsequently patched in version 4.11.7 (commit edbf6eea). Version 3.12.12 predates the feature introduction e...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-24398"
      },
      "impact_statement": "not_affected \u2014 The target repository (Hono version 3.12.12) is not affected by CVE-2026-24398. The vulnerable IP Restriction Middleware feature and its associated IPv4 validation code in `src/utils/ipaddr.ts` do not exist in this version. The feature was introduced in version 4.x (commit 71cdcf40) and subsequently patched in version 4.11.7 (commit edbf6eea). Version 3.12.12 predates the feature introduction e..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-10-01T11:11:44.028700+00:00",
      "status_notes": "Vulnerability CVE-2026-24472 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.3.",
      "vulnerability": {
        "name": "CVE-2026-24472"
      },
      "action_statement": "Vulnerability CVE-2026-24472 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-26T08:59:00.197456+00:00",
      "status_notes": "Vulnerability CVE-2026-24473 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2026-24473"
      },
      "action_statement": "Vulnerability CVE-2026-24473 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-26T08:59:00.197456+00:00",
      "status_notes": "Vulnerability CVE-2026-24771 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2026-24771"
      },
      "action_statement": "Vulnerability CVE-2026-24771 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-24T15:17:19.590664+00:00",
      "status_notes": "Vulnerability CVE-2026-29045 affects version 3.12.12 of hono.",
      "vulnerability": {
        "name": "CVE-2026-29045"
      },
      "action_statement": "Vulnerability CVE-2026-29045 affects version 3.12.12 of hono."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-28T11:46:34.644596+00:00",
      "status_notes": "Vulnerability CVE-2026-29085 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-29085"
      },
      "action_statement": "Vulnerability CVE-2026-29085 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-26T08:59:00.197456+00:00",
      "status_notes": "Vulnerability CVE-2026-29086 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2026-29086"
      },
      "action_statement": "Vulnerability CVE-2026-29086 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-26T08:59:00.197456+00:00",
      "status_notes": "Vulnerability CVE-2026-39407 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2026-39407"
      },
      "action_statement": "Vulnerability CVE-2026-39407 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-24T15:17:19.590664+00:00",
      "status_notes": "Vulnerability CVE-2026-39408 does not affect version 3.12.12 of hono. not_affected \u2014 Version 3.12.12 is not affected by CVE-2026-39408. The SSG (Static Site Generation) feature, which contains the vulnerable toSSG() function with the path traversal issue, does not exist in this version. The SSG helper was introduced in commit 04b686ca after v3.12.12 was released, on a separate development branch (v4.x) that was never backported to the 3.x series. The vulnerability's attack surf...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-39408"
      },
      "impact_statement": "not_affected \u2014 Version 3.12.12 is not affected by CVE-2026-39408. The SSG (Static Site Generation) feature, which contains the vulnerable toSSG() function with the path traversal issue, does not exist in this version. The SSG helper was introduced in commit 04b686ca after v3.12.12 was released, on a separate development branch (v4.x) that was never backported to the 3.x series. The vulnerability's attack surf..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-24T15:17:19.590664+00:00",
      "status_notes": "Vulnerability CVE-2026-39409 does not affect version 3.12.12 of hono. not_affected \u2014 The target repository (Hono v3.12.12) does not contain the vulnerable ipRestriction() middleware. The CVE-2026-39409 vulnerability affects Hono's IP restriction middleware which fails to canonicalize IPv4-mapped IPv6 addresses (::ffff:x.x.x.x) before matching against IPv4 allow/deny rules. However, the ipRestriction middleware was introduced in version 4.x (commit 71cdcf40) and does not exist i...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-39409"
      },
      "impact_statement": "not_affected \u2014 The target repository (Hono v3.12.12) does not contain the vulnerable ipRestriction() middleware. The CVE-2026-39409 vulnerability affects Hono's IP restriction middleware which fails to canonicalize IPv4-mapped IPv6 addresses (::ffff:x.x.x.x) before matching against IPv4 allow/deny rules. However, the ipRestriction middleware was introduced in version 4.x (commit 71cdcf40) and does not exist i..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-26T08:59:00.197456+00:00",
      "status_notes": "Vulnerability CVE-2026-39410 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2026-39410"
      },
      "action_statement": "Vulnerability CVE-2026-39410 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-26T08:59:00.197456+00:00",
      "status_notes": "Vulnerability CVE-2026-44455 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2026-44455"
      },
      "action_statement": "Vulnerability CVE-2026-44455 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-24T15:17:19.590664+00:00",
      "status_notes": "Vulnerability CVE-2026-44456 does not affect version 3.12.12 of hono. not_affected \u2014 The target version 3.12.12 is NOT AFFECTED by CVE-2026-44456. The vulnerability concerns the bodyLimit() middleware's failure to enforce maxSize for chunked requests. However, the bodyLimit middleware component does not exist in version 3.12.12 - it was introduced later in v4.1.0 (138 commits after v3.12.12). Without this middleware component, the vulnerability pattern described in the CVE cann...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-44456"
      },
      "impact_statement": "not_affected \u2014 The target version 3.12.12 is NOT AFFECTED by CVE-2026-44456. The vulnerability concerns the bodyLimit() middleware's failure to enforce maxSize for chunked requests. However, the bodyLimit middleware component does not exist in version 3.12.12 - it was introduced later in v4.1.0 (138 commits after v3.12.12). Without this middleware component, the vulnerability pattern described in the CVE cann..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-26T08:59:00.197456+00:00",
      "status_notes": "Vulnerability CVE-2026-44457 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2026-44457"
      },
      "action_statement": "Vulnerability CVE-2026-44457 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-28T11:46:34.644596+00:00",
      "status_notes": "Vulnerability CVE-2026-44458 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-44458"
      },
      "action_statement": "Vulnerability CVE-2026-44458 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-26T08:59:00.197456+00:00",
      "status_notes": "Vulnerability CVE-2026-44459 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2026-44459"
      },
      "action_statement": "Vulnerability CVE-2026-44459 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-26T08:59:00.197456+00:00",
      "status_notes": "Vulnerability CVE-2026-47673 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2026-47673"
      },
      "action_statement": "Vulnerability CVE-2026-47673 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-24T15:17:19.590664+00:00",
      "status_notes": "Vulnerability CVE-2026-47674 does not affect version 3.12.12 of hono. not_affected \u2014 The target repository (Hono v3.12.12) does not contain the vulnerable ip-restriction middleware. The middleware was introduced in version 4.5.0, significantly after the target version. Exhaustive searches confirm that neither the middleware nor its associated ipaddr utilities (convertIPv6ToBinary, convertIPv4ToBinary, distinctRemoteAddr) exist in the target codebase. The vulnerability cannot ma...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-47674"
      },
      "impact_statement": "not_affected \u2014 The target repository (Hono v3.12.12) does not contain the vulnerable ip-restriction middleware. The middleware was introduced in version 4.5.0, significantly after the target version. Exhaustive searches confirm that neither the middleware nor its associated ipaddr utilities (convertIPv6ToBinary, convertIPv4ToBinary, distinctRemoteAddr) exist in the target codebase. The vulnerability cannot ma..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-28T11:46:34.644596+00:00",
      "status_notes": "Vulnerability CVE-2026-47675 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-47675"
      },
      "action_statement": "Vulnerability CVE-2026-47675 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-24T15:17:19.590664+00:00",
      "status_notes": "Vulnerability CVE-2026-47676 affects version 3.12.12 of hono.",
      "vulnerability": {
        "name": "CVE-2026-47676"
      },
      "action_statement": "Vulnerability CVE-2026-47676 affects version 3.12.12 of hono."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-28T11:46:34.644596+00:00",
      "status_notes": "Vulnerability CVE-2026-54286 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-54286"
      },
      "action_statement": "Vulnerability CVE-2026-54286 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-28T11:46:34.644596+00:00",
      "status_notes": "Vulnerability CVE-2026-54287 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-54287"
      },
      "action_statement": "Vulnerability CVE-2026-54287 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-24T15:17:19.590664+00:00",
      "status_notes": "Vulnerability CVE-2026-54288 does not affect version 3.12.12 of hono. not_affected \u2014 Version 3.12.12 is not affected by CVE-2026-54288. While the Lambda adapters contain the underlying data flaw (they trust the client's Content-Length header without recalculating it based on actual body size), the vulnerability cannot be exploited because the Body Limit Middleware - the component whose security checks would be bypassed - does not exist in this version. The Body Limit Middleware...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-54288"
      },
      "impact_statement": "not_affected \u2014 Version 3.12.12 is not affected by CVE-2026-54288. While the Lambda adapters contain the underlying data flaw (they trust the client's Content-Length header without recalculating it based on actual body size), the vulnerability cannot be exploited because the Body Limit Middleware - the component whose security checks would be bypassed - does not exist in this version. The Body Limit Middleware..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-26T08:59:00.197456+00:00",
      "status_notes": "Vulnerability CVE-2026-54289 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2026-54289"
      },
      "action_statement": "Vulnerability CVE-2026-54289 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-10-03T10:13:00.652366+00:00",
      "status_notes": "Vulnerability CVE-2026-54290 does not affect version 3.12.12 of hono. Hono v3.12.12 is not affected by CVE-2026-54290. The vulnerable origin-reflection behavior was introduced later in v4.12.9 (commit 66fe9fee) and does not exist in this version. The target code always emits Access-Control-Allow-Origin: * (never reflects request origin) when using wildcard origin configuration with credentials, causing browsers to reject the response per CORS spec (fail closed). The vulnerability was subsequently fixed in v4.13.0+ (commit f0b094db) by removing the reflection logic introduced in v4.12.9.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54290"
      },
      "impact_statement": "Hono v3.12.12 is not affected by CVE-2026-54290. The vulnerable origin-reflection behavior was introduced later in v4.12.9 (commit 66fe9fee) and does not exist in this version. The target code always emits Access-Control-Allow-Origin: * (never reflects request origin) when using wildcard origin configuration with credentials, causing browsers to reject the response per CORS spec (fail closed). The vulnerability was subsequently fixed in v4.13.0+ (commit f0b094db) by removing the reflection logic introduced in v4.12.9."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-28T11:46:34.644596+00:00",
      "status_notes": "Vulnerability CVE-2026-56761 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-56761"
      },
      "action_statement": "Vulnerability CVE-2026-56761 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-28T11:46:34.644596+00:00",
      "status_notes": "Vulnerability CVE-2026-56762 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2.",
      "vulnerability": {
        "name": "CVE-2026-56762"
      },
      "action_statement": "Vulnerability CVE-2026-56762 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-10-02T22:50:17.063811+00:00",
      "status_notes": "Vulnerability CVE-2026-56763 does not affect version 3.12.12 of hono. not_affected \u2014 Hono v3.12.12 is not affected by CVE-2026-56763. The vulnerability requires the `parseBody({ dot: true })` option to enable dot notation parsing of form field names. This feature does not exist in v3.12.12 - it was added later in commit 568f8725 (May 23, 2024), which is not an ancestor of this version. The current implementation only supports `ParseBodyOptions.all` and treats form keys literall...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "CVE-2026-56763"
      },
      "impact_statement": "not_affected \u2014 Hono v3.12.12 is not affected by CVE-2026-56763. The vulnerability requires the `parseBody({ dot: true })` option to enable dot notation parsing of form field names. This feature does not exist in v3.12.12 - it was added later in commit 568f8725 (May 23, 2024), which is not an ancestor of this version. The current implementation only supports `ParseBodyOptions.all` and treats form keys literall..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-26T08:59:00.197456+00:00",
      "status_notes": "Vulnerability CVE-2026-69207 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2026-69207"
      },
      "action_statement": "Vulnerability CVE-2026-69207 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-26T08:59:00.197456+00:00",
      "status_notes": "Vulnerability CVE-2026-71850 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2026-71850"
      },
      "action_statement": "Vulnerability CVE-2026-71850 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-26T08:59:00.197456+00:00",
      "status_notes": "Vulnerability CVE-2026-84363 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1.",
      "vulnerability": {
        "name": "CVE-2026-84363"
      },
      "action_statement": "Vulnerability CVE-2026-84363 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-24T15:17:19.590664+00:00",
      "status_notes": "Vulnerability CVE-2026-84364 does not affect version 3.12.12 of hono. not_affected \u2014 The target version 3.12.12 is not affected by CVE-2026-84364. The vulnerability concerns unbounded memory allocation during dot-notation parsing of form field names, but this feature does not exist in version 3.12.12. Dot-notation parsing was introduced in v4.4.0 (commit 568f8725) and the vulnerability was fixed in v4.13.5. The target's body.ts stores dotted keys literally (e.g., \"a.b.c\" as a s...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-84364"
      },
      "impact_statement": "not_affected \u2014 The target version 3.12.12 is not affected by CVE-2026-84364. The vulnerability concerns unbounded memory allocation during dot-notation parsing of form field names, but this feature does not exist in version 3.12.12. Dot-notation parsing was introduced in v4.4.0 (commit 568f8725) and the vulnerability was fixed in v4.13.5. The target's body.ts stores dotted keys literally (e.g., \"a.b.c\" as a s..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-24T15:17:19.590664+00:00",
      "status_notes": "Vulnerability CVE-2026-84365 does not affect version 3.12.12 of hono. not_affected \u2014 The target version 3.12.12 does not contain the SSG (Static Site Generation) feature or any of its vulnerable code. The SSG helper was introduced in Hono v4.0.0, eleven commits after the target version. Since the toSSG() function, ssgParams, and all path normalization utilities (joinPaths, ensureWithinOutDir) do not exist in this version, the vulnerability cannot manifest. The target version pr...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-84365"
      },
      "impact_statement": "not_affected \u2014 The target version 3.12.12 does not contain the SSG (Static Site Generation) feature or any of its vulnerable code. The SSG helper was introduced in Hono v4.0.0, eleven commits after the target version. Since the toSSG() function, ssgParams, and all path normalization utilities (joinPaths, ensureWithinOutDir) do not exist in this version, the vulnerability cannot manifest. The target version pr..."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-10-01T11:11:44.028700+00:00",
      "status_notes": "Vulnerability CVE-2026-93981 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.3.",
      "vulnerability": {
        "name": "CVE-2026-93981"
      },
      "action_statement": "Vulnerability CVE-2026-93981 affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.3."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-28T11:46:34.644596+00:00",
      "status_notes": "Vulnerability GHSA-26pp-8wgv-hjvm affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2.",
      "vulnerability": {
        "name": "GHSA-26pp-8wgv-hjvm"
      },
      "action_statement": "Vulnerability GHSA-26pp-8wgv-hjvm affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.2."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-26T08:59:00.197456+00:00",
      "status_notes": "Vulnerability GHSA-gq3j-xvxp-8hrf affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1.",
      "vulnerability": {
        "name": "GHSA-gq3j-xvxp-8hrf"
      },
      "action_statement": "Vulnerability GHSA-gq3j-xvxp-8hrf affects version 3.12.12 of hono, and is fixed in 3.12.12-tuxcare.1."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-24T15:17:19.590664+00:00",
      "status_notes": "Vulnerability GHSA-q7jf-gf43-6x6p does not affect version 3.12.12 of hono. not_affected \u2014 Target version 3.12.12 is NOT AFFECTED. The vulnerable code pattern (reading the Vary header from HTTP requests and reflecting it into responses) does not exist in this version. This vulnerability was introduced in v4.4.5 (June 2024) via commit 1a32ef4d and fixed in v4.10.3 (October 2025) via commit d9b8b4b7. Version 3.12.12, released in February 2024, predates the introduction of the vulnerabi...",
      "justification": "vulnerable_code_not_in_execute_path",
      "vulnerability": {
        "name": "GHSA-q7jf-gf43-6x6p"
      },
      "impact_statement": "not_affected \u2014 Target version 3.12.12 is NOT AFFECTED. The vulnerable code pattern (reading the Vary header from HTTP requests and reflecting it into responses) does not exist in this version. This vulnerability was introduced in v4.4.5 (June 2024) via commit 1a32ef4d and fixed in v4.10.3 (October 2025) via commit d9b8b4b7. Version 3.12.12, released in February 2024, predates the introduction of the vulnerabi..."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/hono@3.12.12",
          "identifiers": {
            "purl": "pkg:npm/hono@3.12.12"
          }
        }
      ],
      "timestamp": "2026-09-24T15:17:19.590664+00:00",
      "status_notes": "Vulnerability GHSA-v8w9-8mx6-g223 does not affect version 3.12.12 of hono. not_affected \u2014 The target repository (Hono v3.12.12) is not affected by GHSA-v8w9-8mx6-g223. The vulnerability requires the `dot: true` option in `parseBody()` which enables dot notation parsing to create nested objects. This feature was introduced in Hono v4.4.0 (commit 568f8725). The target version v3.12.12 predates this feature and only performs literal string key assignment (`form[key] = value`), making i...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "GHSA-v8w9-8mx6-g223"
      },
      "impact_statement": "not_affected \u2014 The target repository (Hono v3.12.12) is not affected by GHSA-v8w9-8mx6-g223. The vulnerability requires the `dot: true` option in `parseBody()` which enables dot notation parsing to create nested objects. This feature was introduced in Hono v4.4.0 (commit 568f8725). The target version v3.12.12 predates this feature and only performs literal string key assignment (`form[key] = value`), making i..."
    }
  ]
}
