Skip to content

chore: Update @hono/node-server to 2.0.10 [SECURITY] - #220

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-hono-node-server-vulnerability
Open

chore: Update @hono/node-server to 2.0.10 [SECURITY]#220
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-hono-node-server-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Aug 8, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@hono/node-server >=2.0.6>=2.0.10 age adoption passing confidence

Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake

GHSA-9mqv-5hh9-4cgg

More information

Details

Summary

A WebSocket upgrade request to an upgradeWebSocket route with a missing or malformed Sec-WebSocket-Key header leaks memory permanently. The request's IncomingMessage is retained in an internal map and a pending promise is never settled, even though no connection is established. Since the route is reachable pre-handshake without authentication, an unauthenticated attacker can flood it to gradually exhaust memory.

Details

The built-in WebSocket helper cleans up its internal map only on a successful handshake or when the route guard rejects the request. When ws aborts the handshake because Sec-WebSocket-Key is missing or malformed, no connection event is emitted, so neither cleanup path runs and the entry is retained forever. A present-but-malformed key leaks identically, so a proxy that only checks for the header's presence does not mitigate it.

Impact

An unauthenticated attacker can flood any public upgradeWebSocket route with malformed-key upgrade requests, causing unbounded memory growth and eventual loss of availability. No confidentiality or integrity impact.

Reported by @​TarPeg007.

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake

GHSA-9mqv-5hh9-4cgg

More information

Details

Summary

A WebSocket upgrade request to an upgradeWebSocket route with a missing or malformed Sec-WebSocket-Key header leaks memory permanently. The request's IncomingMessage is retained in an internal map and a pending promise is never settled, even though no connection is established. Since the route is reachable pre-handshake without authentication, an unauthenticated attacker can flood it to gradually exhaust memory.

Details

The built-in WebSocket helper cleans up its internal map only on a successful handshake or when the route guard rejects the request. When ws aborts the handshake because Sec-WebSocket-Key is missing or malformed, no connection event is emitted, so neither cleanup path runs and the entry is retained forever. A present-but-malformed key leaks identically, so a proxy that only checks for the header's presence does not mitigate it.

Impact

An unauthenticated attacker can flood any public upgradeWebSocket route with malformed-key upgrade requests, causing unbounded memory growth and eventual loss of availability. No confidentiality or integrity impact.

Reported by @​TarPeg007.

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

honojs/node-server (@​hono/node-server)

v2.0.10

Compare Source

Security fixes

This release includes a fix for the following security issue:

Unauthenticated memory-leak DoS via aborted WebSocket handshake

Affects: upgradeWebSocket. A WebSocket upgrade request with a missing or malformed Sec-WebSocket-Key header leaked the request's IncomingMessage and left a promise pending, even though no connection was established. Since the route is reachable pre-handshake without authentication, an attacker could flood it to gradually exhaust memory. GHSA-9mqv-5hh9-4cgg


Users of upgradeWebSocket are encouraged to upgrade to this version.

v2.0.9

Compare Source

What's Changed

  • fix(websocket): polyfill missing ErrorEvent global by @​otnc in #​371
  • fix(serve-static): correct Range header parsing edge cases by @​otnc in #​372
  • fix: recover complete request bodies after client disconnect by @​usualoma in #​375

New Contributors

Full Changelog: honojs/node-server@v2.0.8...v2.0.9

v2.0.8

Compare Source

What's Changed

Full Changelog: honojs/node-server@v2.0.7...v2.0.8


Configuration

📅 Schedule: (in timezone Asia/Kolkata)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from chitrank2050 as a code owner August 8, 2026 18:48
@renovate
renovate Bot enabled auto-merge (squash) August 8, 2026 18:48
@chitrank-actions chitrank-actions Bot added the area/deps Dependency upgrades and lockfile updates label Aug 8, 2026
@renovate renovate Bot changed the title chore: Update @hono/node-server to 2.1.0 [SECURITY] chore: Update @hono/node-server to 2.0.10 [SECURITY] Aug 8, 2026
@renovate
renovate Bot force-pushed the renovate/npm-hono-node-server-vulnerability branch from 3ffb735 to 751f5c8 Compare August 8, 2026 20:52
@renovate renovate Bot changed the title chore: Update @hono/node-server to 2.0.10 [SECURITY] chore: Update @hono/node-server to 2.1.0 [SECURITY] Aug 11, 2026
@renovate
renovate Bot force-pushed the renovate/npm-hono-node-server-vulnerability branch from 751f5c8 to c952e2d Compare August 11, 2026 22:46
@renovate
renovate Bot force-pushed the renovate/npm-hono-node-server-vulnerability branch from c952e2d to 2f81f9b Compare August 12, 2026 05:46
@renovate renovate Bot changed the title chore: Update @hono/node-server to 2.1.0 [SECURITY] chore: Update @hono/node-server to 2.0.10 [SECURITY] Aug 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/deps Dependency upgrades and lockfile updates security vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants