GHSA-g6gw-c38x-mqfc

    Dashboard / Vulnerabilities / GHSA-g6gw-c38x-mqfc

    GHSA-g6gw-c38x-mqfc

    Published: 8 Sept 2026Last Modified: 8 Sept 2026

    Summary: Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion

    Details: ### Summary When `parseBody()` expands dot-separated form field names into nested objects, it does not limit the nesting depth or the total number of objects created. A request body well within a normal size limit can therefore allocate an object graph far larger than the request itself, and concurrent requests can exhaust the heap and terminate the process. ### Details Each dot-separated segment of a field name creates an intermediate object. Neither the segments within a single field name nor the total across a request was bounded, and empty segments were preserved, so a field name could encode one nesting level per byte. Both shapes produce the effect: a single deeply dotted field name, and a large number of shallowly dotted ones within one body. A request body size limit does not prevent it, because the amplification happens after the body has been accepted. Dot-notation parsing is not enabled by default. ### Impact An attacker who can reach an endpoint that parses request bodies with dot-notation enabled can send concurrent requests whose memory cost is disproportionate to their size. This may lead to: - exhaustion of the JavaScript heap and termination of the server process - the service remaining unavailable until it is restarted This issue affects applications that explicitly enable dot-notation parsing. Applications using the default behaviour are not affected.

    Affected packages

    Package

    Name: hono

    Purl: pkg:npm/hono

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -4.13.5

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High