{"apiVersion":"1.0","identifier":"CVE-2026-73565","description":"@hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request to an upgradeWebSocket route with a missing or malformed Sec-WebSocket-Key header causes src/websocket.ts to retain the request-s IncomingMessage in waiterMap and leave waitForWebSocket pending because ws.handleUpgrade emits no connection event. The aborted handshake therefore has no cleanup path, allowing an unauthenticated attacker to flood a public route, cause unbounded memory growth, and eventually make the service unavailable. This issue is fixed in version 2.0.10.","publishedAt":"2026-08-13T18:18:19","lastModifiedAt":"2026-08-14T17:20:33","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73565","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","epssProbability":0.00388,"riskScore":0.55,"affectedProduct":"@hono/node-server","affectedVersions":">=2.0.0, <=2.0.10","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-73565","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-73565","en":"https://www.redsauce.net/en/cves/CVE-2026-73565","fr":"https://www.redsauce.net/fr/cves/CVE-2026-73565","pt":"https://www.redsauce.net/pt/cves/CVE-2026-73565","de":"https://www.redsauce.net/de/cves/CVE-2026-73565","sk":"https://www.redsauce.net/sk/cves/CVE-2026-73565","el":"https://www.redsauce.net/el/cves/CVE-2026-73565"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-73565"}}