CVE-2024-48913 - CVE House
Back to Database
Status published Medium CVE-2024-48913

Hono vulnerable to bypass of CSRF Middleware by a request without Content-Type header.

Vulnerability Description

Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by a request without Content-Type header. Although the CSRF middleware verifies the Content-Type Header, Hono always considers a request without a Content-Type header to be safe. This can allow an attacker to bypass CSRF protection implemented with Hono CSRF middleware. Version 4.6.5 fixes this issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-48913

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

hono
Vulnerable Versions:
< 4.6.5

Timeline

Official Publish: October 15th, 2024
Last Modified: November 7th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N

Weaknesses (CWE)