GHSA-g6gw-c38x-mqfc
Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion
Quick fix
GHSA-g6gw-c38x-mqfc — hono: upgrade to the fixed version with the command below.
npm install hono@4.13.5Details
### Summary
When `parseBody()` expands dot-separated form field names into nested objects, it does not limit the nesting depth or the total number of objects created. A request body well within a normal size limit can therefore allocate an object graph far larger than the request itself, and concurrent requests can exhaust the heap and terminate the process.
### Details
Each dot-separated segment of a field name creates an intermediate object. Neither the segments within a single field name nor the total across a request was bounded, and empty segments were preserved, so a field name could encode one nesting level per byte.
Both shapes produce the effect: a single deeply dotted field name, and a large number of shallowly dotted ones within one body. A request body size limit does not prevent it, because the amplification happens after the body has been accepted.
Dot-notation parsing is not enabled by default.
### Impact
An attacker who can reach an endpoint that parses request bodies with dot-notation enabled can send concurrent requests whose memory cost is disproportionate to their size.
This may lead to:
- exhaustion of the JavaScript heap and termination of the server process - the service remaining unavailable until it is restarted
This issue affects applications that explicitly enable dot-notation parsing. Applications using the default behaviour are not affected.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/honojs/hono/security/advisories/GHSA-g6gw-c38x-mqfc[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-84364[ADVISORY]
- https://github.com/honojs/hono/commit/531e9c5a3ae058d10de33f643055bd4009a87178[WEB]
- https://github.com/honojs/hono[PACKAGE]
- https://github.com/honojs/hono/releases/tag/v4.13.5[WEB]