CVE-2017-16013
Expert Analysis
Professional remediation guidance
Get tailored security recommendations from our analyst team for CVE-2017-16013. We'll provide specific mitigation strategies based on your environment and risk profile.
Description
hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught exception is thrown. This may cause hapi to crash or to hang the client connection until the timeout period is reached.
Available Exploits
Related News
Affected Products
Affected Versions:
GitHub Security Advisories
Community-driven vulnerability intelligence from GitHub
Denial of Service via malformed accept-encoding header in hapi
GHSA-cqjg-whmm-8gv6Advisory Details
Affected Packages
CVSS Scoring
CVSS Score
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References
Advisory provided by GitHub Security Advisory Database. Published: October 9, 2018, Modified: September 7, 2023