Race condition in hono - CVE-2023-50710
Published: December 14, 2023 / Updated: July 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause unintended resource modification or a denial of service.
The vulnerability exists due to improper handling of named path parameters in TrieRouter when processing concurrent requests. A remote attacker can send crafted requests that override parameter values from other requests to cause unintended resource modification or a denial of service.
User interaction is required to trigger the vulnerable request handling.