Information Exposure Through Timing Discrepancy in hono - CVE-2026-56764
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to observable timing discrepancies in basicAuth and bearerAuth middlewares when comparing authentication hash values during request processing. A remote attacker can send authentication attempts and measure response timing differences to disclose sensitive information.
Exploitation is only theoretically possible under highly controlled conditions where precise timing measurements are possible.