CVE-2024-32652: @hono/node-server contains Denial of Service risk when receiving Host header that cannot be parsed

Published Apr 19, 2024
·
Updated

Impact

The application hangs when receiving a Host header with a value that @hono/node-server can't handle well. Invalid values are those that cannot be parsed by the URL as a hostname such as an empty string, slashes /, and other strings.

For example, if you have a simple application:

ts import { serve } from '@hono/node-server' import { Hono } from 'hono'

const app = new Hono()

app.get('/', (c) => c.text('Hello'))

serve(app)

Sending a request with a Host header with an empty value to it:

curl localhost:3000/ -H "Host: "

The results:

node:internal/url:775 this.#updateContext(bindingUrl.parse(input, base)); ^

TypeError: Invalid URL at new URL (node:internal/url:775:36) at newRequest (/Users/yusuke/work/h/159/nodemodules/@hono/node-server/dist/index.js:137:17) at Server.<anonymous> (/Users/yusuke/work/h/159/nodemodules/@hono/node-server/dist/index.js:399:17) at Server.emit (node:events:514:28) at Server.emit (node:domain:488:12) at parserOnIncoming (node:httpserver:1143:12) at HTTPParser.parserOnHeadersComplete (node:httpcommon:119:17) { code: 'ERRINVALIDURL', input: 'http:///' }

Patches

The version 1.10.1 includes the fix for this issue. But, you should use 1.11.0, which has other fixes related to this issue. https://github.com/honojs/node-server/issues/160 https://github.com/honojs/node-server/issues/161

Workarounds

Nothing. Upgrade your @hono/node-server.

References

https://github.com/honojs/node-server/issues/159

Other sources

The adapter @hono/node-server allows you to run your Hono application on Node.js. Prior to 1.10.1, the application hangs when receiving a Host header with a value that @hono/node-server can't handle well. Invalid values are those that cannot be parsed by the URL as a hostname such as an empty string, slashes /, and other strings. The version 1.10.1 includes the fix for this issue.

NVD

Affected Software

2 affected componentsFixes available
npm/@hono/node-server>=1.3.0<1.10.1
1.10.1
Hono Node-server Node.js>=1.3.0<1.10.1

Event History

Apr 19, 2024
CVE Published
via MITRE·06:29 PM
Data Sourced
via MITRE·06:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
RemedyAffected Software
Advisory Published
via GitHub·07:48 PM

Frequently Asked Questions

1

What is the severity of CVE-2024-32652?

CVE-2024-32652 has a severity rating that suggests a significant impact due to the application hang condition.

2

How do I fix CVE-2024-32652?

To mitigate CVE-2024-32652, update the @hono/node-server package to version 1.10.1 or later.

3

What specific versions of @hono/node-server are affected by CVE-2024-32652?

CVE-2024-32652 affects versions of @hono/node-server from 1.3.0 to 1.10.0.

4

What actions lead to the vulnerability in CVE-2024-32652?

The vulnerability in CVE-2024-32652 is triggered when the application receives an improperly formatted Host header.

5

What symptoms indicate an issue caused by CVE-2024-32652?

Symptoms of CVE-2024-32652 include the application hanging or becoming unresponsive when processing invalid Host header values.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203