Regular Expression Denial of Service in hawk
High severity
GitHub Reviewed
Published
Jul 31, 2018
to the GitHub Advisory Database
•
Updated Apr 11, 2023
Description
Published to the GitHub Advisory Database
Jul 31, 2018
Reviewed
Jun 16, 2020
Last updated
Apr 11, 2023
Versions of
hawk
prior to 3.1.3, or 4.x prior to 4.1.1 are affected by a regular expression denial of service vulnerability related to excessively long headers and URI's.Recommendation
Update to hawk version 4.1.1 or later.
References