Vulnerability record · CVE-2024-32652 · published 19 April 2024
CVE-2024-32652: Hono node-server vulnerability
Hono · Node Server
The adapter @hono/node-server allows you to run your Hono application on Node.js. Prior to 1.10.1, the application hangs when receiving a Host header with a value that `@hono/node-server` can't handle well. Invalid values are those that cannot be parsed by the `URL` as a hostname such as an empty string, slashes `/`, and other strings. The version 1.10.1 includes the fix for this issue.
Description
The adapter @hono/node-server allows you to run your Hono application on Node.js. Prior to 1.10.1, the application hangs when receiving a Host header with a value that `@hono/node-server` can't handle well. Invalid values are those that cannot be parsed by the `URL` as a hostname such as an empty string, slashes `/`, and other strings. The version 1.10.1 includes the fix for this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/honojs/node-server/commit/d847e60249fd8183ba0998bc379ba20505643204 | Patch |
| https://github.com/honojs/node-server/issues/159 | ExploitIssue TrackingThird Party Advisory |
| https://github.com/honojs/node-server/security/advisories/GHSA-hgxw-5xg3-69jx | Vendor Advisory |
| https://github.com/honojs/node-server/commit/d847e60249fd8183ba0998bc379ba20505643204 | Patch |
| https://github.com/honojs/node-server/issues/159 | ExploitIssue TrackingThird Party Advisory |
| https://github.com/honojs/node-server/security/advisories/GHSA-hgxw-5xg3-69jx | Vendor Advisory |
Track CVE-2024-32652 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-32652), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.