Executive brief
A vulnerability in the Hono web framework allows attackers to bypass request size limits when sending data in chunks. This means that even if a developer has set a maximum allowed size for incoming data to protect the server, an attacker can bypass this restriction. This could lead to unexpected resource consumption or the processing of oversized data by the application's business logic.
Technical details
The bodyLimit() middleware in Hono (npm package) fails to strictly enforce the maxSize constraint for requests without a usable Content-Length header, such as those using 'Transfer-Encoding: chunked'. The root cause is that the middleware wraps the request body in an asynchronous stream to count bytes but allows the application handler to execute before the size validation is finalized. If a handler returns a response without reading the full body, or if it catches and ignores read errors, it can return a successful 200 OK status for a request that exceeds the configured limit. This bypasses the documented guarantee that oversized requests are rejected before business logic runs. The issue is fixed in version 4.12.16 by enforcing the size check before the next middleware or handler executes.
Affected products
- honojs hono < 4.12.16
Timeline
- 2026-04-30: disclosed: Initial disclosure by yusukebe
- 2026-05-06: advisory: GitHub Advisory published
- 2026-05-13: other: NVD published date