GHSA-54fx-42gc-7vw4: Medium severity npm/hono vulnerability
Summary
The languageDetector middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen-separated subtags.
Details
To implement progressive language-tag truncation, normalizeLanguage() repeatedly calls parts.slice(0, i).join('-') for every possible prefix. The total amount of string processing grows quadratically with the number of subtags.
Language values may come from a query parameter, cookie, Accept-Language header, or URL path, depending on the detector configuration. The default detector order enables query-string, cookie, and header detection, so applications using languageDetector() may expose this processing to unauthenticated requests.
Request-size limits reduce the maximum cost of a single request but do not eliminate the issue. Inputs accepted by common JavaScript runtimes can still cause noticeable synchronous event-loop blocking.
Impact
An attacker may repeatedly send requests containing long, hyphen-separated language tags, causing excessive CPU consumption and preventing unrelated requests from being processed.
The practical impact depends on the runtime's request-size limits, reverse-proxy configuration, and the detectors enabled by the application.
Resolution
The progressive lookup should avoid reconstructing every shorter prefix. The implementation can instead inspect the configured supported languages and select the longest value that matches the input at a hyphen boundary.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/honoto a version that resolves this vulnerability.Fixed in 4.12.34
Event History
Frequently Asked Questions
What is the severity of GHSA-54fx-42gc-7vw4?
The severity of GHSA-54fx-42gc-7vw4 is medium with a score of 5.3.
What type of attack does GHSA-54fx-42gc-7vw4 expose to?
GHSA-54fx-42gc-7vw4 exposes systems to algorithmic complexity denial of service attacks.
How do I fix GHSA-54fx-42gc-7vw4?
To fix GHSA-54fx-42gc-7vw4, update your npm/hono package to the recommended secure version that implements fixes.
What software is affected by GHSA-54fx-42gc-7vw4?
The GHSA-54fx-42gc-7vw4 vulnerability affects the npm/hono software.
When was GHSA-54fx-42gc-7vw4 published?
GHSA-54fx-42gc-7vw4 was published on August 7, 2026.