CVE-2026-44455

Published
View on NVD ↗
CVSS v3
4.7
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, Improper handling of JSX element tag names in hono/jsx allowed unvalidated tag names to be directly inserted into the generated HTML output. When untrusted input is used as a tag name via the programmatic jsx() or createElement() APIs during server-side rendering, specially crafted values may break out of the intended element context and inject unintended HTML. This vulnerability is fixed in 4.12.16.

Web framework built on Web Standards
GitHubGitHub
30.8K