{"id":"GHSA-9mqv-5hh9-4cgg","summary":"Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake","details":"## Summary\n\nA WebSocket upgrade request to an `upgradeWebSocket` route with a missing or malformed `Sec-WebSocket-Key` header leaks memory permanently. The request's `IncomingMessage` is retained in an internal map and a pending promise is never settled, even though no connection is established. Since the route is reachable pre-handshake without authentication, an unauthenticated attacker can flood it to gradually exhaust memory.\n\n## Details\n\nThe built-in WebSocket helper cleans up its internal map only on a successful handshake or when the route guard rejects the request. When `ws` aborts the handshake because `Sec-WebSocket-Key` is missing or malformed, no `connection` event is emitted, so neither cleanup path runs and the entry is retained forever. A present-but-malformed key leaks identically, so a proxy that only checks for the header's presence does not mitigate it.\n\n## Impact\n\nAn unauthenticated attacker can flood any public `upgradeWebSocket` route with malformed-key upgrade requests, causing unbounded memory growth and eventual loss of availability. No confidentiality or integrity impact.\n\nReported by @TarPeg007.","aliases":["CVE-2026-73565"],"modified":"2026-08-13T17:55:56.703914Z","published":"2026-07-21T22:04:27Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-07-21T22:04:27Z","nvd_published_at":null,"cwe_ids":["CWE-401","CWE-770"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/honojs/node-server/security/advisories/GHSA-9mqv-5hh9-4cgg"},{"type":"WEB","url":"https://github.com/honojs/node-server/commit/3a21938c418340e980cb7ffa88e78369f78392d1"},{"type":"PACKAGE","url":"https://github.com/honojs/node-server"},{"type":"WEB","url":"https://github.com/honojs/node-server/releases/tag/v2.0.10"}],"affected":[{"package":{"name":"@hono/node-server","ecosystem":"npm","purl":"pkg:npm/%40hono/node-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0"},{"fixed":"2.0.10"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.0.9","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-9mqv-5hh9-4cgg/GHSA-9mqv-5hh9-4cgg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}