216.73.216.36

CVE-2026-24472

· Published 27/01/2026 20:16 · Modified 27/01/2026 20:16

Labels: CVE-2026-24472 2026-01-27CVE-2026-24472CWE-524[email protected]

Essential information

Published
27/01/2026 20:16
Modified
27/01/2026 20:16
Author
Creator
CVSS
5.3 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS metrics

Description

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Cache Middleware contains an information disclosure vulnerability caused by improper handling of HTTP cache control directives. The middleware does not respect standard cache control headers such as `Cache-Control: private` or `Cache-Control: no-store`, which may result in private or authenticated responses being cached and subsequently exposed to unauthorized users. Version 4.11.7 has a patch for the issue.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
* / hono cpe:2.3:a:*:hono:<4.11.7:*:*:*:*:*:*:*
* / hono cpe:2.3:a:*:hono:*:*:*:*:*:*:*:*

References