CVE-2026-24473: Hono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)
(updated )
Serve static Middleware for the Cloudflare Workers adapter contains an information disclosure vulnerability that may allow attackers to read arbitrary keys from the Workers environment. Improper validation of user-controlled paths can result in unintended access to internal asset keys.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-24473 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →