<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:05:47 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-5162</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-5162</link>
      <description>EUVD-2026-5162</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-5162</guid>
    </item>
    <item>
      <title>fkie_cve-2024-32652</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-32652</link>
      <description>&lt;p&gt;The adapter @hono/node-server allows you to run your Hono application on Node.js. Prior to 1.10.1, the application hangs when receiving a Host header with a value that `@hono/node-server` can&amp;#39;t handle well. Invalid values are those that cannot be parsed by the `URL` as a hostname such as an empty string, slashes `/`, and other strings. The version 1.10.1 includes the fix for this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The adapter @hono/node-server allows you to run your Hono application on Node.js. Prior to 1.10.1, the application hangs when receiving a Host header with a value that `@hono/node-server` can&amp;#39;t handle well. Invalid values are those that cannot be parsed by the `URL` as a hostname such as an empty string, slashes `/`, and other strings. The version 1.10.1 includes the fix for this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-32652</guid>
    </item>
    <item>
      <title>GHSA-hgxw-5xg3-69jx — @hono/node-server has Denial of Service risk when receiving Host header that cannot be parsed</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hgxw-5xg3-69jx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @hono/node-server&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The application hangs when receiving a Host header with a value that `@hono/node-server` can&amp;#39;t handle well. Invalid values are those that cannot be parsed by the `URL` as a hostname such as an empty string, slashes `/`, and other strings.&lt;/p&gt;
&lt;p&gt;For example, if you have a simple application:&lt;/p&gt;
&lt;p&gt;```ts
import { serve } from &amp;#39;@hono/node-server&amp;#39;
import { Hono } from &amp;#39;hono&amp;#39;&lt;/p&gt;
&lt;p&gt;const app = new Hono()&lt;/p&gt;
&lt;p&gt;app.get(&amp;#39;/&amp;#39;, (c) =&amp;gt; c.text(&amp;#39;Hello&amp;#39;))&lt;/p&gt;
&lt;p&gt;serve(app)
```&lt;/p&gt;
&lt;p&gt;Sending a request with a Host header with an empty value to it:&lt;/p&gt;
&lt;p&gt;```
curl localhost:3000/ -H &amp;#34;Host: &amp;#34;
```&lt;/p&gt;
&lt;p&gt;The results:&lt;/p&gt;
&lt;p&gt;```
node:internal/url:775
    this.#updateContext(bindingUrl.parse(input, base));
                                   ^&lt;/p&gt;
&lt;p&gt;TypeError: Invalid URL
    at new URL (node:internal/url:775:36)
    at newRequest (/Users/yusuke/work/h/159/node_modules/@hono/node-server/dist/index.js:137:17)
    at Server.&amp;lt;anonymous&amp;gt; (/Users/yusuke/work/h/159/node_modules/@hono/node-server/dist/index.js:399:17)
    at Server.emit (node:events:514:28)
    at Server.emit (node:domain:488:12)
    at parserOnIncoming (node:_http_server:1143:12)
    at HTTPParser.parserOnHeadersComplete (node:_http_common:119:17) {
  code: &amp;#39;ERR_INVALID_URL&amp;#39;,
  input: &amp;#39;http:///&amp;#39;
}
```&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The version `1.10.1` includes the fix for this issue. But, you should use `1.11.0`, which has other fixes related to this issue. https://github.com/honojs/node-server/issues/160 https://github.com/honojs/node-server/issues/161&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Nothing. Upgrade your…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @hono/node-server&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The application hangs when receiving a Host header with a value that `@hono/node-server` can&amp;#39;t handle well. Invalid values are those that cannot be parsed by the `URL` as a hostname such as an empty string, slashes `/`, and other strings.&lt;/p&gt;
&lt;p&gt;For example, if you have a simple application:&lt;/p&gt;
&lt;p&gt;```ts
import { serve } from &amp;#39;@hono/node-server&amp;#39;
import { Hono } from &amp;#39;hono&amp;#39;&lt;/p&gt;
&lt;p&gt;const app = new Hono()&lt;/p&gt;
&lt;p&gt;app.get(&amp;#39;/&amp;#39;, (c) =&amp;gt; c.text(&amp;#39;Hello&amp;#39;))&lt;/p&gt;
&lt;p&gt;serve(app)
```&lt;/p&gt;
&lt;p&gt;Sending a request with a Host header with an empty value to it:&lt;/p&gt;
&lt;p&gt;```
curl localhost:3000/ -H &amp;#34;Host: &amp;#34;
```&lt;/p&gt;
&lt;p&gt;The results:&lt;/p&gt;
&lt;p&gt;```
node:internal/url:775
    this.#updateContext(bindingUrl.parse(input, base));
                                   ^&lt;/p&gt;
&lt;p&gt;TypeError: Invalid URL
    at new URL (node:internal/url:775:36)
    at newRequest (/Users/yusuke/work/h/159/node_modules/@hono/node-server/dist/index.js:137:17)
    at Server.&amp;lt;anonymous&amp;gt; (/Users/yusuke/work/h/159/node_modules/@hono/node-server/dist/index.js:399:17)
    at Server.emit (node:events:514:28)
    at Server.emit (node:domain:488:12)
    at parserOnIncoming (node:_http_server:1143:12)
    at HTTPParser.parserOnHeadersComplete (node:_http_common:119:17) {
  code: &amp;#39;ERR_INVALID_URL&amp;#39;,
  input: &amp;#39;http:///&amp;#39;
}
```&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The version `1.10.1` includes the fix for this issue. But, you should use `1.11.0`, which has other fixes related to this issue. https://github.com/honojs/node-server/issues/160 https://github.com/honojs/node-server/issues/161&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Nothing. Upgrade your…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hgxw-5xg3-69jx</guid>
    </item>
    <item>
      <title>gsd-2024-32652</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-32652</link>
      <description>gsd-2024-32652</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-32652</guid>
    </item>
  </channel>
</rss>
