Loading HuntDB...

GHSA-cqjg-whmm-8gv6

GitHub Security Advisory

Denial of Service via malformed accept-encoding header in hapi

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Affected versions of `hapi` will crash or lock the event loop when a malformed `accept-encoding` header is recieved.

## Recommendation

Update to version 16.1.1 or later.

Affected Packages

npm hapi
Affected versions: 15.0.0 (fixed in 16.1.1)

Related CVEs

Key Information

GHSA ID
GHSA-cqjg-whmm-8gv6
Published
October 9, 2018 12:57 AM
Last Modified
September 7, 2023 8:33 PM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
hapi
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 3, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.