PT-2026-5013 · Cloudflare+1 · Cloudflare Workers+1

·

CVE-2026-24473

·

Published

2026-01-27

·

Updated

2026-02-04

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Hono versions prior to 4.11.7
Description The Serve static Middleware for the Cloudflare Workers adapter in Hono does not properly validate user-controlled paths, potentially allowing attackers to read arbitrary keys from the Workers environment. This improper validation can result in unintended access to internal asset keys. The issue affects applications running on Cloudflare Workers that utilize Serve static Middleware with user-controllable request paths and may lead to information disclosure. The exposed data is limited to readable asset keys and does not allow modification of stored data or execution of arbitrary code.
Recommendations Update to Hono version 4.11.7 or later.

Exploit

Fix

Improper Access Control

Information Disclosure

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-24473
GHSA-W332-Q679-J88P

Affected Products

Cloudflare Workers
Hono