CVE-2026-56764
Hono added timing comparison hardening in basicAuth and bearerAuth
描述
## Summary The `basicAuth` and `bearerAuth` middlewares previously used a comparison that was not fully timing-safe. The `timingSafeEqual` function used normal string equality (`===`) when comparing hash values. This comparison may stop early if values differ, which can theoretically cause small timing differences. The implementation has been updated to use a safer comparison method. ## Details The issue was caused by the use of normal string equality (`===`) when comparing hash values inside the `timingSafeEqual` function. In JavaScript, string comparison may stop as soon as a difference is found. This means the comparison time can slightly vary depending on how many characters match. Under very specific and controlled conditions, this behavior could theoretically allow timing-based analysis. The implementation has been updated to: - Avoid early termination during comparison - Use a constant-time-style comparison method ## Impact This issue is unlikely to be exploited in normal environments. It may only be relevant in highly controlled situations where precise timing measurements are possible. This change is considered a security hardening improvement. Users are encouraged to upgrade to the latest version.
如何修補 CVE-2026-56764
要修補 CVE-2026-56764,請將受影響套件升級到下列已修補版本。
- —升級至 4.11.10 或更新版本
CVE-2026-56764 正在被利用嗎?
低 — EPSS 為 0.2%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 4.11.10
CVSS 分數
| 來源 | 版本 |
|---|