PT-2026-5013 · Cloudflare+1 · Cloudflare Workers+1
Kilkat
·
Published
2026-01-27
·
Updated
2026-02-04
·
CVE-2026-24473
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Hono versions prior to 4.11.7
Description
The Serve static Middleware for the Cloudflare Workers adapter in Hono does not properly validate user-controlled paths, potentially allowing attackers to read arbitrary keys from the Workers environment. This improper validation can result in unintended access to internal asset keys. The issue affects applications running on Cloudflare Workers that utilize Serve static Middleware with user-controllable request paths and may lead to information disclosure. The exposed data is limited to readable asset keys and does not allow modification of stored data or execution of arbitrary code.
Recommendations
Update to Hono version 4.11.7 or later.
Exploit
Fix
Improper Access Control
Exposure of Resource to Wrong Sphere
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cloudflare Workers
Hono