Intel

AIKIDO-2025-10111

@hono/node-ws is vulnerable to Resource Leak

Resource Leak Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 25, 2025

35

Low Risk

This Affects:

JS@hono/node-ws
1.0.2 - 1.0.8
Fixed in 1.1.0
Are you affected? Scan for Free

TL;DR

Affected versions of the package suffer from resource leaks due to a flaw in WebSocket connection handling. WebSocket connections remain open indefinitely, even when the application does not expect them. As a result, these unintended connections can consume system resources, potentially leading to performance degradation and other unintended behavior.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@hono/node-ws is vulnerable to Resource Leak in versions 1.0.2 - 1.0.8.

How to fix this

Upgrade the @hono/node-ws library to the patch version.