{"id":"GHSA-hm8q-7f3q-5f36","summary":"Hono has improper validation of NumericDate claims (exp, nbf, iat) in JWT verify()","details":"### Summary\n\nImproper validation of the JWT NumericDate claims `exp`, `nbf`, and `iat` in `hono/utils/jwt` allows tokens with non-spec-compliant claim values to silently bypass time-based checks. This issue is not exploitable by an anonymous attacker; it only manifests when a malformed claim value reaches `verify()` — typically when the application itself issues such tokens, or when the signing key is otherwise under attacker control.\n\n### Details\n\nThe validation routine combined option, presence, and threshold checks in a single short-circuiting expression, so several classes of malformed values were silently skipped instead of rejected:\n\n- A falsy numeric value short-circuited the presence check.\n- A non-finite numeric value compared as never-after-now and never-expired.\n- A non-numeric type produced NaN comparisons that evaluated false.\n\nThis deviates from RFC 7519 §4.1.4, which defines NumericDate as a finite JSON numeric value.\n\n### Impact\n\nAn actor able to issue tokens accepted by the application may craft tokens whose `exp`, `nbf`, or `iat` claims silently bypass time-based enforcement. This may lead to:\n\n- Tokens treated as never expiring even with `exp` configured on the verifier.\n- Tokens with a future `nbf` accepted as currently valid.\n- Tokens with a future `iat` accepted as legitimately issued.\n\nDeployments using a well-formed token issuer and protecting the signing key are not affected.","aliases":["CVE-2026-44459"],"modified":"2026-05-14T20:51:33.926067Z","published":"2026-05-09T00:45:19Z","related":["CGA-h8g8-rw22-w672"],"database_specific":{"cwe_ids":["CWE-1284"],"github_reviewed_at":"2026-05-09T00:45:19Z","github_reviewed":true,"nvd_published_at":"2026-05-13T16:16:57Z","severity":"LOW"},"references":[{"type":"WEB","url":"https://github.com/honojs/hono/security/advisories/GHSA-hm8q-7f3q-5f36"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44459"},{"type":"PACKAGE","url":"https://github.com/honojs/hono"}],"affected":[{"package":{"name":"hono","ecosystem":"npm","purl":"pkg:npm/hono"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.12.18"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-hm8q-7f3q-5f36/GHSA-hm8q-7f3q-5f36.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"}]}