Improper access control in hono - CVE-2026-24473
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in serve-static middleware for the Cloudflare Workers adapter when handling user-controlled request paths for static assets. A remote attacker can send a specially crafted request to disclose sensitive information.
Only applications running on Cloudflare Workers that use the serve-static middleware with user-controllable request paths are vulnerable.