GHSA-9mqv-5hh9-4cgg

Suggest an improvement
Source
https://github.com/advisories/GHSA-9mqv-5hh9-4cgg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-9mqv-5hh9-4cgg/GHSA-9mqv-5hh9-4cgg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9mqv-5hh9-4cgg
Aliases
Published
2026-07-21T22:04:27Z
Modified
2026-08-13T17:55:56Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
Details

Summary

A WebSocket upgrade request to an upgradeWebSocket route with a missing or malformed Sec-WebSocket-Key header leaks memory permanently. The request's IncomingMessage is retained in an internal map and a pending promise is never settled, even though no connection is established. Since the route is reachable pre-handshake without authentication, an unauthenticated attacker can flood it to gradually exhaust memory.

Details

The built-in WebSocket helper cleans up its internal map only on a successful handshake or when the route guard rejects the request. When ws aborts the handshake because Sec-WebSocket-Key is missing or malformed, no connection event is emitted, so neither cleanup path runs and the entry is retained forever. A present-but-malformed key leaks identically, so a proxy that only checks for the header's presence does not mitigate it.

Impact

An unauthenticated attacker can flood any public upgradeWebSocket route with malformed-key upgrade requests, causing unbounded memory growth and eventual loss of availability. No confidentiality or integrity impact.

Reported by @TarPeg007.

Database specific
{
    "cwe_ids":  [
        "CWE-401",
        "CWE-770"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-21T22:04:27Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / @hono/node-server

Package

Name
@hono/node-server
View open source insights on deps.dev
Purl
pkg:npm/%40hono/node-server

Affected ranges

Type
SEMVER
Events
Introduced
2.0.0
Fixed
2.0.10

Database specific

last_known_affected_version_range
"<= 2.0.9"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-9mqv-5hh9-4cgg/GHSA-9mqv-5hh9-4cgg.json"