VDB
Sign up
HIGH7.5

GHSA-jcpv-g9rr-qxrc

Regular Expression Denial of Service in hawk

Quick fix

GHSA-jcpv-g9rr-qxrc — hawk: upgrade to the fixed version with the command below.

npm install hawk@4.1.1

Details

Versions of `hawk` prior to 3.1.3, or 4.x prior to 4.1.1 are affected by a regular expression denial of service vulnerability related to excessively long headers and URI's.

## Recommendation

Update to hawk version 4.1.1 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/hawk
Introduced in: 4.0.0Fixed in: 4.1.1
Fixnpm install hawk@4.1.1
npm/hawk
Introduced in: 0Fixed in: 3.1.3
Fixnpm install hawk@3.1.3

References