mongodb/node-mongodb-native · error · MongoRuntimeError

Server returned an invalid host

Error message

Server returned an invalid host: "${host}"

What it means

Thrown during MONGODB-AWS SASL exchange when the host returned by the server fails validation: length is 0, length exceeds 255, or it contains '..'. The host is used to build the STS GetCallerIdentity request URL, so an invalid value would enable host injection/path traversal and is rejected.

Solutions

  1. Ensure you are connecting to a legitimate MongoDB server endpoint.
  2. Remove intermediary proxies that could rewrite the response host field.
  3. Report to the server vendor if the host field is unexpectedly malformed.
Defensive patterns

Strategy: try-catch

Try / catch

try {
  await client.connect();
} catch (e) {
  if (e instanceof MongoRuntimeError && /invalid host/.test(e.message)) {
    // inspect server endpoint / proxy; possible host injection
  }
  throw e;
}

Prevention

When it happens

Trigger: serverResponse.h is empty, longer than 255 chars, or contains '..'. Fires at mongodb_aws.ts:95. Indicates a malformed server response or a malicious/buggy endpoint.

Common situations: A proxy injecting an unexpected host. A non-MongoDB endpoint responding to the saslStart command. Corrupted BSON.

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/8ca04947dd62c976. Report an issue: GitHub.

Appendix: source

Thrown at src/cmap/auth/mongodb_aws.ts:95

    };
    const host = serverResponse.h;
    const serverNonce = serverResponse.s.buffer;
    if (serverNonce.length !== 64) {
      // TODO(NODE-3483)
      throw new MongoRuntimeError(`Invalid server nonce length ${serverNonce.length}, expected 64`);
    }

    if (!ByteUtils.equals(serverNonce.subarray(0, nonce.byteLength), nonce)) {
      // throw because the serverNonce's leading 32 bytes must equal the client nonce's 32 bytes
      // https://github.com/mongodb/specifications/blob/master/source/auth/auth.md#conversation-5

      // TODO(NODE-3483)
      throw new MongoRuntimeError('Server nonce does not begin with client nonce');
    }

    if (host.length < 1 || host.length > 255 || host.indexOf('..') !== -1) {
      // TODO(NODE-3483)
      throw new MongoRuntimeError(`Server returned an invalid host: "${host}"`);
    }

    const body = 'Action=GetCallerIdentity&Version=2011-06-15';
    const headers = await aws4Sign(
      {
        method: 'POST',
        host,
        region: deriveRegion(serverResponse.h),
        service: 'sts',
        headers: {
          'Content-Type': 'application/x-www-form-urlencoded',
          'Content-Length': body.length,
          'X-MongoDB-Server-Nonce': ByteUtils.toBase64(serverNonce),
          'X-MongoDB-GS2-CB-Flag': 'n'
        },
        path: '/',
        body,
        date: new Date()

View on GitHub (pinned to dce7939f86)