<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:09:29.248745+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-5162</id>
    <title>EUVD-2026-5162</title>
    <updated>2026-10-03T07:09:29.253852+00:00</updated>
    <content>EUVD-2026-5162</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-5162"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-32652</id>
    <title>fkie_cve-2024-32652</title>
    <updated>2026-10-03T07:09:29.253905+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The adapter @hono/node-server allows you to run your Hono application on Node.js. Prior to 1.10.1, the application hangs when receiving a Host header with a value that `@hono/node-server` can't handle well. Invalid values are those that cannot be parsed by the `URL` as a hostname such as an empty string, slashes `/`, and other strings. The version 1.10.1 includes the fix for this issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-32652"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hgxw-5xg3-69jx</id>
    <title>GHSA-hgxw-5xg3-69jx — @hono/node-server has Denial of Service risk when receiving Host header that cannot be parsed</title>
    <updated>2026-10-03T07:09:29.253958+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @hono/node-server</p>
<p>### Impact</p>
<p>The application hangs when receiving a Host header with a value that `@hono/node-server` can't handle well. Invalid values are those that cannot be parsed by the `URL` as a hostname such as an empty string, slashes `/`, and other strings.</p>
<p>For example, if you have a simple application:</p>
<p>```ts
import { serve } from '@hono/node-server'
import { Hono } from 'hono'</p>
<p>const app = new Hono()</p>
<p>app.get('/', (c) =&gt; c.text('Hello'))</p>
<p>serve(app)
```</p>
<p>Sending a request with a Host header with an empty value to it:</p>
<p>```
curl localhost:3000/ -H "Host: "
```</p>
<p>The results:</p>
<p>```
node:internal/url:775
    this.#updateContext(bindingUrl.parse(input, base));
                                   ^</p>
<p>TypeError: Invalid URL
    at new URL (node:internal/url:775:36)
    at newRequest (/Users/yusuke/work/h/159/node_modules/@hono/node-server/dist/index.js:137:17)
    at Server.&lt;anonymous&gt; (/Users/yusuke/work/h/159/node_modules/@hono/node-server/dist/index.js:399:17)
    at Server.emit (node:events:514:28)
    at Server.emit (node:domain:488:12)
    at parserOnIncoming (node:_http_server:1143:12)
    at HTTPParser.parserOnHeadersComplete (node:_http_common:119:17) {
  code: 'ERR_INVALID_URL',
  input: 'http:///'
}
```</p>
<p>### Patches</p>
<p>The version `1.10.1` includes the fix for this issue. But, you should use `1.11.0`, which has other fixes related to this issue. https://github.com/honojs/node-server/issues/160 https://github.com/honojs/node-server/issues/161</p>
<p>### Workarounds</p>
<p>Nothing. Upgrade your…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hgxw-5xg3-69jx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-32652</id>
    <title>gsd-2024-32652</title>
    <updated>2026-10-03T07:09:29.254042+00:00</updated>
    <content>gsd-2024-32652</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-32652"/>
  </entry>
</feed>
