hapijs/hawk

hapijs/hawk

Releases67
Frequency2 months 20 hours
Last Release

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
= 4.1.0, = 3.1.2, >= 4.0.0, < 4.1.1, < 3.1.37.8 HIGH

Hawk before 3.1.3 and 4.x before 4.1.1 allow remote attackers to cause a denial of service (CPU consumption or partial outage) via a long (1) header or (2) URI that is matched against an improper regular expression.