4.8
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
CVE-2026-54289 affects the npm hono JavaScript web framework (fixed in 4.12.25). This package is Eclipse Hono, an unrelated Java/Quarkus IoT connectivity framework that shares only the project name and contains none of the affected JavaScript code.
Status