VDB
Sign up
HIGH

GHSA-7hx8-2rxv-66xv

Denial of Service in hapi

Details

All Versions of `hapi` are vulnerable to Denial of Service. The CORS request handler has a vulnerability which will cause the function to throw a system error if the header contains some invalid values. If no unhandled exception handler is available, the application will exist, allowing an attacker to shut down services.

## Recommendation

This package is deprecated and is now maintained as `@hapi/hapi`. Please update your dependencies to use `@hapi/hapi`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/hapi
Introduced in: 0.0.0

No fixed version published yet for hapi (npm). Pin to a known-safe version or switch to an alternative.

References