Description
Versions of hawk prior to 3.1.3, or 4.x prior to 4.1.1 are affected by a regular expression denial of service vulnerability related to excessively long headers and URI’s.
Recommendation
Update the hawk package to the latest compatible version. Followings are version details:
Affected version(s): **>= 4.0.0, < 4.1.1 < 3.1.3** Patched version(s): **4.1.1 3.1.3**
References
Could your website be exposed too?
SmartScanner can check your website for Regular Expression Denial of Service in hawk and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Regular Expression Denial of Service in jadedown - CVE-2016-10520
- Regular Expression Denial of Service in riot-compiler - CVE-2016-10527
- Regular Expression Denial of Service in moment - moment - CVE-2016-4055
- glob-parent 6.0.0 vulnerable to Regular Expression Denial of Service - CVE-2021-35065
You might also like:
See something that needs correcting? Let us knowUpdated April 11, 2023


