VDB
KO
MEDIUM 5.3

GHSA-54fx-42gc-7vw4

Hono: Algorithmic Complexity DoS in Language Middleware

Quick fix

GHSA-54fx-42gc-7vw4 — hono: upgrade to the fixed version with the command below.

npm install hono@4.12.34

Details

### Summary

The `languageDetector` middleware is vulnerable to algorithmic complexity denial of service when processing a crafted language tag containing a large number of hyphen-separated subtags.

### Details

To implement progressive language-tag truncation, `normalizeLanguage()` repeatedly calls `parts.slice(0, i).join('-')` for every possible prefix. The total amount of string processing grows quadratically with the number of subtags.

Language values may come from a query parameter, cookie, `Accept-Language` header, or URL path, depending on the detector configuration. The default detector order enables query-string, cookie, and header detection, so applications using `languageDetector()` may expose this processing to unauthenticated requests.

Request-size limits reduce the maximum cost of a single request but do not eliminate the issue. Inputs accepted by common JavaScript runtimes can still cause noticeable synchronous event-loop blocking.

### Impact

An attacker may repeatedly send requests containing long, hyphen-separated language tags, causing excessive CPU consumption and preventing unrelated requests from being processed.

The practical impact depends on the runtime's request-size limits, reverse-proxy configuration, and the detectors enabled by the application.

### Resolution

The progressive lookup should avoid reconstructing every shorter prefix. The implementation can instead inspect the configured supported languages and select the longest value that matches the input at a hyphen boundary.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / hono
Introduced in: 4.12.0 Fixed in: 4.12.34
Fix npm install hono@4.12.34

References