Asymmetric denial of service - ReDoS In hawk
Description
Regular Expression Denial of Service in hawk
Versions of hawk prior to 3.1.3, or 4.x prior to 4.1.1 are affected by a regular expression denial of service vulnerability related to excessively long headers and URI's.
Recommendation
Update to hawk version 4.1.1 or later.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 4.1.1, 3.1.3 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4. 5. 6.