PT-2026-5013 · Cloudflare+1 · Cloudflare Workers+1

Kilkat

·

Published

2026-01-27

·

Updated

2026-02-04

·

CVE-2026-24473

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Hono versions prior to 4.11.7
Description The Serve static Middleware for the Cloudflare Workers adapter in Hono does not properly validate user-controlled paths, potentially allowing attackers to read arbitrary keys from the Workers environment. This improper validation can result in unintended access to internal asset keys. The issue affects applications running on Cloudflare Workers that utilize Serve static Middleware with user-controllable request paths and may lead to information disclosure. The exposed data is limited to readable asset keys and does not allow modification of stored data or execution of arbitrary code.
Recommendations Update to Hono version 4.11.7 or later.

Exploit

Fix

Improper Access Control

Exposure of Resource to Wrong Sphere

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-24473
GHSA-W332-Q679-J88P

Affected Products

Cloudflare Workers
Hono