Skip to content

Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback)

High severity GitHub Reviewed Published Jan 13, 2026 in honojs/hono • Updated Jan 13, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts