Allocation of Resources Without Limits or Throttling Affecting @hono/node-server package, versions >=2.0.0 <2.0.10


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-HONONODESERVER-18170429
  • published22 Jul 2026
  • disclosed21 Jul 2026
  • creditSaad FELLAHI

Introduced: 21 Jul 2026

New CVE NOT AVAILABLE CWE-401  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade @hono/node-server to version 2.0.10 or higher.

Overview

@hono/node-server is a Node.js Adapter for Hono

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the upgradeWebSocket. An attacker can cause unbounded memory consumption by sending repeated WebSocket upgrade requests with missing or malformed Sec-WebSocket-Key headers, resulting in permanent retention of request objects and eventual exhaustion of system memory.

CVSS Base Scores

version 4.0
version 3.1