{"id":"GHSA-g6gw-c38x-mqfc","summary":"Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion","details":"### Summary\n\nWhen `parseBody()` expands dot-separated form field names into nested objects, it does not limit the nesting depth or the total number of objects created. A request body well within a normal size limit can therefore allocate an object graph far larger than the request itself, and concurrent requests can exhaust the heap and terminate the process.\n\n### Details\n\nEach dot-separated segment of a field name creates an intermediate object. Neither the segments within a single field name nor the total across a request was bounded, and empty segments were preserved, so a field name could encode one nesting level per byte.\n\nBoth shapes produce the effect: a single deeply dotted field name, and a large number of shallowly dotted ones within one body. A request body size limit does not prevent it, because the amplification happens after the body has been accepted.\n\nDot-notation parsing is not enabled by default.\n\n### Impact\n\nAn attacker who can reach an endpoint that parses request bodies with dot-notation enabled can send concurrent requests whose memory cost is disproportionate to their size.\n\nThis may lead to:\n\n- exhaustion of the JavaScript heap and termination of the server process\n- the service remaining unavailable until it is restarted\n\nThis issue affects applications that explicitly enable dot-notation parsing. Applications using the default behaviour are not affected.","aliases":["CVE-2026-84364"],"modified":"2026-09-08T21:30:04.377804608Z","published":"2026-09-08T21:23:02Z","database_specific":{"cwe_ids":["CWE-400"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-09-08T21:23:02Z","nvd_published_at":"2026-09-01T21:18:47Z"},"references":[{"type":"WEB","url":"https://github.com/honojs/hono/security/advisories/GHSA-g6gw-c38x-mqfc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84364"},{"type":"WEB","url":"https://github.com/honojs/hono/commit/531e9c5a3ae058d10de33f643055bd4009a87178"},{"type":"PACKAGE","url":"https://github.com/honojs/hono"},{"type":"WEB","url":"https://github.com/honojs/hono/releases/tag/v4.13.5"}],"affected":[{"package":{"name":"hono","ecosystem":"npm","purl":"pkg:npm/hono"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.13.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-g6gw-c38x-mqfc/GHSA-g6gw-c38x-mqfc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}