Information Exposure Through Timing Discrepancy in hono - CVE-2026-56764

 

Information Exposure Through Timing Discrepancy in hono - CVE-2026-56764

Published: July 24, 2026


Vulnerability identifier: #VU139316
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-56764
CWE-ID: CWE-208
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to observable timing discrepancies in basicAuth and bearerAuth middlewares when comparing authentication hash values during request processing. A remote attacker can send authentication attempts and measure response timing differences to disclose sensitive information.

Exploitation is only theoretically possible under highly controlled conditions where precise timing measurements are possible.


Affected software

hono

How to mitigate CVE-2026-56764

Install security update from vendor's website.

hono - update to 4.11.10

External References

Related Security Bulletins