A AegiFlow
MEDIUMCVSS 5.3EPSS 0.4%

CVE-2026-73565

CVE-2026-73565 updated by NVD

Published
2026-07-21
Modified
2026-09-12
EPSS percentile
32%
Sources
github-advisory, nvd

Summary

@hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request to an upgradeWebSocket route with a missing or malformed Sec-WebSocket-Key header causes src/websocket.ts to retain the request's IncomingMessage in waiterMap and leave waitForWebSocket pending because ws.handleUpgrade emits no connection event. The aborted handshake therefore has no cleanup path, allowing an unauthenticated attacker to flood a public route, cause unbounded memory growth, and eventually make the service unavailable. This issue is fixed in version 2.0.10.

Affected packages

EcosystemPackageAffected versionsFixed versions
npm@hono/node-server2.0.10

Remediation: Upgrade to 2.0.10 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.