PT-2025-37316 · Hono · Hono

Imenyoo2

+1

·

Published

2025-09-12

·

Updated

2025-09-17

·

CVE-2025-59139

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions: Hono versions prior to 4.9.7
Description: Hono is a Web application framework that provides support for any JavaScript runtime. A flaw in the bodyLimit middleware could allow bypassing the configured request body size limit when conflicting HTTP headers were present. The middleware previously prioritized the Content-Length header even when a Transfer-Encoding: chunked header was also included, which is a discrepancy with the HTTP specification. This could allow oversized request bodies to bypass the configured limit, potentially leading to denial of service (DoS) due to excessive memory or CPU consumption when handling very large requests.
Recommendations: Upgrade to Hono version 4.9.7 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2025-59139
GHSA-92VJ-G62V-JQHH

Affected Products

Hono