Description
Versions of hawk prior to 3.1.3, or 4.x prior to 4.1.1 are affected by a regular expression denial of service vulnerability related to excessively long headers and URI’s.
Recommendation
Update the hawk package to the latest compatible version. Followings are version details:
Affected version(s): **>= 4.0.0, < 4.1.1 < 3.1.3** Patched version(s): **4.1.1 3.1.3**
References
- GHSA-jcpv-g9rr-qxrc
- www.npmjs.com
- bugzilla.redhat.com
- www.openwall.com
- CVE-2016-2515
- CWE-1333
- CAPEC-310
- OWASP 2021-A6
Related Issues
- Regular Expression Denial of Service in jadedown - CVE-2016-10520
- Regular Expression Denial of Service in riot-compiler - CVE-2016-10527
- Regular Expression Denial of Service in moment - moment - CVE-2016-4055
- glob-parent 6.0.0 vulnerable to Regular Expression Denial of Service - CVE-2021-35065
You might also like:
- Tags:
- npm
- hawk
Anything's wrong? Let us know Last updated on April 11, 2023


