CVE-2025-59139: Hono has Body Limit Middleware Bypass
Summary A flaw in the bodyLimit middleware could allow bypassing the configured request body size limit when conflicting HTTP headers were present.
Details The middleware previously prioritized the Content-Length header even when a Transfer-Encoding: chunked header was also included. According to the HTTP specification, Content-Length must be ignored in such cases. This discrepancy could allow oversized request bodies to bypass the configured limit.
Most standards-compliant runtimes and reverse proxies may reject such malformed requests with 400 Bad Request, so the practical impact depends on the runtime and deployment environment.
Impact If body size limits are used as a safeguard against large or malicious requests, this flaw could allow attackers to send oversized request bodies. The primary risk is denial of service (DoS) due to excessive memory or CPU consumption when handling very large requests.
Resolution The implementation has been updated to align with the HTTP specification, ensuring that Transfer-Encoding takes precedence over Content-Length. The issue is fixed in Hono v4.9.7, and all users should upgrade immediately.
Other sources
Hono is a Web application framework that provides support for any JavaScript runtime. In versions prior to 4.9.7, a flaw in the bodyLimit middleware could allow bypassing the configured request body size limit when conflicting HTTP headers were present. The middleware previously prioritized the Content-Length header even when a Transfer-Encoding: chunked header was also included. According to the HTTP specification, Content-Length must be ignored in such cases. This discrepancy could allow oversized request bodies to bypass the configured limit. Most standards-compliant runtimes and reverse proxies may reject such malformed requests with 400 Bad Request, so the practical impact depends on the runtime and deployment environment. If body size limits are used as a safeguard against large or malicious requests, this flaw could allow attackers to send oversized request bodies. The primary risk is denial of service (DoS) due to excessive memory or CPU consumption when handling very large requests. The implementation has been updated to align with the HTTP specification, ensuring that Transfer-Encoding takes precedence over Content-Length. The issue is fixed in Hono v4.9.7, and all users should upgrade immediately.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59139?
The CVE-2025-59139 vulnerability is classified as a moderate severity issue due to its potential for bypassing request body size limits.
How do I fix CVE-2025-59139?
To fix CVE-2025-59139, upgrade the Hono Body Limit Middleware to version 4.9.7 or later, which addresses this flaw.
What causes the vulnerability in CVE-2025-59139?
CVE-2025-59139 is caused by a flaw in the `bodyLimit` middleware that allows bypassing the request body size limit when conflicting HTTP headers are present.
Which versions of Hono are affected by CVE-2025-59139?
Versions of the Hono Body Limit Middleware prior to 4.9.7 are affected by CVE-2025-59139.
What is the impact of CVE-2025-59139 on applications?
The impact of CVE-2025-59139 is that it may allow attackers to send larger request bodies than intended, potentially leading to denial of service or other unintended behaviors.