CVE-2026-73565 | honojs node-server up to 2.0.9 WebSocket Upgrade src/websocket.ts ws.handleUpgrade Sec-WebSocket-Key allocation of resources

SecurityVulns

A vulnerability marked as problematic has been reported in honojs node-server up to 2.0.9. Affected is the function ws.handleUpgrade of the file src/websocket.ts of the component WebSocket Upgrade. The manipulation of the argument Sec-WebSocket-Key leads to allocation of resources.

This vulnerability is traded as CVE-2026-73565. It is possible to initiate the attack remotely. There is no exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More