Intel

AIKIDO-2026-10172

@cap-js/hana is vulnerable to Denial of Service (DoS)

Denial of Service (DoS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

42

Medium Risk

This Affects:

JS@cap-js/hana
1.3.1 - 2.5.1
Fixed in 2.6.0

TL;DR

Affected versions of this package are vulnerable to denial of service due to improper handling of invalid credentials during connection pool failures. The service manager repeatedly attempts to fetch and use invalid credentials without triggering backoff logic, which can cause excessive requests and lead to service disruption.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@cap-js/hana is vulnerable to Denial of Service (DoS) in versions 1.3.1 - 2.5.1.

How to fix this

Upgrade the @cap-js/hana library to the patch version.

Background Info