← Vulnerability feed

Vulnerability record · CVE-2024-32652 · published 19 April 2024

CVE-2024-32652: Hono node-server vulnerability

Hono · Node Server

The adapter @hono/node-server allows you to run your Hono application on Node.js. Prior to 1.10.1, the application hangs when receiving a Host header with a value that `@hono/node-server` can't handle well. Invalid values are those that cannot be parsed by the `URL` as a hostname such as an empty string, slashes `/`, and other strings. The version 1.10.1 includes the fix for this issue.

7.5 CVSS 3.1 High EPSS 0.88% · top 42.5% CWE-755 · CWE-755
7.5CVSS 3.1 base score
0.88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The adapter @hono/node-server allows you to run your Hono application on Node.js. Prior to 1.10.1, the application hangs when receiving a Host header with a value that `@hono/node-server` can't handle well. Invalid values are those that cannot be parsed by the `URL` as a hostname such as an empty string, slashes `/`, and other strings. The version 1.10.1 includes the fix for this issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-32652 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2026-29087Hono node-server incorrect authorization vulnerability@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving togeth…EPSS 0.41%5.3CVE-2026-39406Hono node-server path traversal vulnerability@hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in serveStatic allows protected sta…EPSS 0.40%5.3CVE-2024-23340Hono node-server path traversal vulnerability@hono/node-server is an adapter that allows users to run Hono applications on Node.js. Since v1.3.0, @hono/node-server has used its own Request objec…EPSS 0.72%7.8CVE-2024-29748Android Pixel logic error allows local privilege escalationCVE-2024-29748 is a logic error in Android code that permits bypassing a security check, leading to local escalation of privilege. It affects Google …KEVEPSS 0.67%analysed9.8CVE-2020-7247OpenSMTPD MAIL FROM command injection allows remote root code executionOpenSMTPD 6.6, as shipped in OpenBSD 6.6 and other products, mishandles input validation in smtp_mailaddr in smtp_session.c, returning an incorrect v…KEVEPSS 99%analysed8.6CVE-2018-0155Cisco Catalyst BFD offload incomplete header handling denial of serviceCisco Catalyst 4500 and 4500-X series switches mishandle incomplete BFD headers in the BFD offload implementation, causing the iosd process to crash.…KEVEPSS 7.7%analysed8.8CVE-2021-38003Google Chrome V8 heap corruption via crafted HTML pageGoogle Chrome before 95.0.4638.69 contains an inappropriate implementation in the V8 JavaScript engine that can lead to heap corruption. A remote att…KEVEPSS 39%analysed9.8CVE-2017-5638Apache Struts 2 Jakarta Multipart parser remote code executionThe Jakarta Multipart parser in Apache Struts 2 mishandles exceptions and error messages during file-upload attempts, letting a crafted Content-Type,…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2024-32652), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.