CVE-2024-32652: @hono/node-server contains Denial of Service risk when receiving Host header that cannot be parsed
Impact
The application hangs when receiving a Host header with a value that @hono/node-server can't handle well. Invalid values are those that cannot be parsed by the URL as a hostname such as an empty string, slashes /, and other strings.
For example, if you have a simple application:
ts import { serve } from '@hono/node-server' import { Hono } from 'hono'
const app = new Hono()
app.get('/', (c) => c.text('Hello'))
serve(app)
Sending a request with a Host header with an empty value to it:
curl localhost:3000/ -H "Host: "
The results:
node:internal/url:775 this.#updateContext(bindingUrl.parse(input, base)); ^
TypeError: Invalid URL at new URL (node:internal/url:775:36) at newRequest (/Users/yusuke/work/h/159/nodemodules/@hono/node-server/dist/index.js:137:17) at Server.<anonymous> (/Users/yusuke/work/h/159/nodemodules/@hono/node-server/dist/index.js:399:17) at Server.emit (node:events:514:28) at Server.emit (node:domain:488:12) at parserOnIncoming (node:httpserver:1143:12) at HTTPParser.parserOnHeadersComplete (node:httpcommon:119:17) { code: 'ERRINVALIDURL', input: 'http:///' }
Patches
The version 1.10.1 includes the fix for this issue. But, you should use 1.11.0, which has other fixes related to this issue. https://github.com/honojs/node-server/issues/160 https://github.com/honojs/node-server/issues/161
Workarounds
Nothing. Upgrade your @hono/node-server.
References
https://github.com/honojs/node-server/issues/159
Other sources
The adapter @hono/node-server allows you to run your Hono application on Node.js. Prior to 1.10.1, the application hangs when receiving a Host header with a value that @hono/node-server can't handle well. Invalid values are those that cannot be parsed by the URL as a hostname such as an empty string, slashes /, and other strings. The version 1.10.1 includes the fix for this issue.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32652?
CVE-2024-32652 has a severity rating that suggests a significant impact due to the application hang condition.
How do I fix CVE-2024-32652?
To mitigate CVE-2024-32652, update the @hono/node-server package to version 1.10.1 or later.
What specific versions of @hono/node-server are affected by CVE-2024-32652?
CVE-2024-32652 affects versions of @hono/node-server from 1.3.0 to 1.10.0.
What actions lead to the vulnerability in CVE-2024-32652?
The vulnerability in CVE-2024-32652 is triggered when the application receives an improperly formatted Host header.
What symptoms indicate an issue caused by CVE-2024-32652?
Symptoms of CVE-2024-32652 include the application hanging or becoming unresponsive when processing invalid Host header values.