GHSA-54fx-42gc-7vw4

    Dashboard / Vulnerabilities / GHSA-54fx-42gc-7vw4

    GHSA-54fx-42gc-7vw4

    Published: 7 Aug 2026Last Modified: 10 Aug 2026

    Summary: Hono: Algorithmic Complexity DoS in Language Middleware

    Details: ### Summary The `languageDetector` middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen-separated subtags. ### Details To implement progressive language-tag truncation, `normalizeLanguage()` repeatedly calls `parts.slice(0, i).join('-')` for every possible prefix. The total amount of string processing grows quadratically with the number of subtags. Language values may come from a query parameter, cookie, `Accept-Language` header, or URL path, depending on the detector configuration. The default detector order enables query-string, cookie, and header detection, so applications using `languageDetector()` may expose this processing to unauthenticated requests. Request-size limits reduce the maximum cost of a single request but do not eliminate the issue. Inputs accepted by common JavaScript runtimes can still cause noticeable synchronous event-loop blocking. ### Impact An attacker may repeatedly send requests containing long, hyphen-separated language tags, causing excessive CPU consumption and preventing unrelated requests from being processed. The practical impact depends on the runtime's request-size limits, reverse-proxy configuration, and the detectors enabled by the application. ### Resolution The progressive lookup should avoid reconstructing every shorter prefix. The implementation can instead inspect the configured supported languages and select the longest value that matches the input at a hyphen boundary.

    Affected packages

    Package

    Name: hono

    Purl: pkg:npm/hono

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 4.12.0
    Fixed -4.12.34

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High