Package
hono-compat
Component
hono-compat
Latest update
5.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
This detection is a package-name collision. The advisory concerns the npm hono JavaScript web framework, in which the CORS middleware is vulnerable to regular expression denial of service; this package is the unrelated Eclipse Hono IoT connectivity framework, a Java/Quarkus application that shares only the project name and contains no JavaScript. The vulnerable code is not present, so the issue does not apply.
Status