mediumCVSS 5.3Vulnerability

CVE-2026-84364

### Summary When `parseBody()` expands dot-separated form field names into nested objects, it does not limit the nesting depth or the total number of objects created. A request body well within a normal size limit can therefore allocate an object graph far larger than the request itself, and concurrent requests can exhaust the heap and terminate the process. ### Details Each dot-separated segment of a field name creates an intermediate object. Neither the segments within a single field name nor the total across a request was bounded, and empty segments were preserved, so a field name could encode one nesting level per byte. Both shapes produce the effect: a single deeply dotted field name, and a large number of shallowly dotted ones within one body. A request body size limit does not prevent it, because the amplification happens after the body has been accepted. Dot-notation parsing is not enabled by default. ### Impact An attacker who can reach an endpoint that parses request bodies with dot-notation enabled can send concurrent requests whose memory cost is disproportionate to their size. This may lead to: - exhaustion of the JavaScript heap and termination of the server process - the service remaining unavailable until it is restarted This issue affects applications that explicitly enable dot-notation parsing. Applications using the default behaviour are not affected.

Properties

severity
medium
summary
Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion
epss_score
0.00388
cvss_score
5.3
ghsa_published
2026-09-08T21:23:02Z
source_url
https://github.com/advisories/GHSA-g6gw-c38x-mqfc
ghsa_updated
2026-09-08T21:23:04Z
ghsa_id
GHSA-g6gw-c38x-mqfc
cve_id
CVE-2026-84364
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
is_ghsa_only
false
epss_percentile
0.32038

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS (1)

[Software]npm/hono

HAS_WEAKNESS (1)

[Weakness]Uncontrolled Resource Consumption

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/hono

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-84364 (CVSS 5.3) — Ninja Signal Threat Intelligence | Ninja Signal