lowCVSS 3.7Vulnerability

GHSA-gq3j-xvxp-8hrf

## Summary The `basicAuth` and `bearerAuth` middlewares previously used a comparison that was not fully timing-safe. The `timingSafeEqual` function used normal string equality (`===`) when comparing hash values. This comparison may stop early if values differ, which can theoretically cause small timing differences. The implementation has been updated to use a safer comparison method. ## Details The issue was caused by the use of normal string equality (`===`) when comparing hash values inside the `timingSafeEqual` function. In JavaScript, string comparison may stop as soon as a difference is found. This means the comparison time can slightly vary depending on how many characters match. Under very specific and controlled conditions, this behavior could theoretically allow timing-based analysis. The implementation has been updated to: - Avoid early termination during comparison - Use a constant-time-style comparison method ## Impact This issue is unlikely to be exploited in normal environments. It may only be relevant in highly controlled situations where precise timing measurements are possible. This change is considered a security hardening improvement. Users are encouraged to upgrade to the latest version.

Properties

ghsa_id
GHSA-gq3j-xvxp-8hrf
severity
low
summary
Hono added timing comparison hardening in basicAuth and bearerAuth
cvss_score
3.7
cve_id
GHSA-gq3j-xvxp-8hrf
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
is_ghsa_only
true
ghsa_published
2026-02-19T20:15:59Z
source_url
https://github.com/advisories/GHSA-gq3j-xvxp-8hrf
ghsa_updated
2026-02-19T20:16:02Z

Related Entities (3)

AFFECTS (1)

[Software]npm/hono

HAS_WEAKNESS (1)

[Weakness]Observable Timing Discrepancy

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-gq3j-xvxp-8hrf (CVSS 3.7) — Ninja Signal Threat Intelligence | Ninja Signal