Improper Authorization in hono - CVE-2025-62610
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized cross-service access.
The vulnerability exists due to improper authorization in the JWT authentication middleware when processing JWTs without audience validation. A remote attacker can present a valid token issued for a different audience to gain unauthorized cross-service access.
User interaction is required.