Lucene search

K
osvGoogleOSV:GHSA-JCPV-G9RR-QXRC
HistoryJul 31, 2018 - 10:52 p.m.

Regular Expression Denial of Service in hawk

2018-07-3122:52:00
Google
osv.dev
8

0.023 Low

EPSS

Percentile

89.8%

Versions of hawk prior to 3.1.3, or 4.x prior to 4.1.1 are affected by a regular expression denial of service vulnerability related to excessively long headers and URI’s.

Recommendation

Update to hawk version 4.1.1 or later.

CPENameOperatorVersion
hawkge4.0.0
hawklt4.1.1
hawklt3.1.3

0.023 Low

EPSS

Percentile

89.8%

Related for OSV:GHSA-JCPV-G9RR-QXRC