Executive brief
Hono is a popular web framework for building fast web applications. A flaw in its request body size limit enforcement allows attackers to send oversized requests by exploiting how the framework handles conflicting HTTP headers. This could lead to denial of service attacks that consume excessive server resources, causing service degradation or outages.
Technical details
The vulnerability is a request smuggling/header parsing issue in Hono's bodyLimit middleware. The middleware incorrectly prioritized the Content-Length header over Transfer-Encoding: chunked, violating HTTP specifications that mandate Transfer-Encoding takes precedence when both are present. This allows attackers to bypass the configured body size limit by crafting requests with conflicting headers, potentially enabling unbounded memory or CPU consumption. The attack requires only network access and no authentication. The vulnerability affects Hono versions up to 4.9.6 and is fixed in version 4.9.7. Most standards-compliant runtimes may reject such malformed requests, reducing practical impact in some deployments.
Affected products
- Hono Hono <=4.9.6
Timeline
- 2025-09-12: disclosed
- 2025-09-12: patched: Fixed in Hono v4.9.7