QID 983765
QID 983765: Nodejs (npm) Security Update for hawk (GHSA-jcpv-g9rr-qxrc)
Versions of `hawk` prior to 3.1.3, or 4.x prior to 4.1.1 are affected by a regular expression denial of service vulnerability related to excessively long headers and URI's. ## Recommendation Update to hawk version 4.1.1 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-jcpv-g9rr-qxrc for updates pertaining to this vulnerability.
Vendor References
- GHSA-jcpv-g9rr-qxrc -
github.com/advisories/GHSA-jcpv-g9rr-qxrc
CVEs related to QID 983765
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jcpv-g9rr-qxrc | hawk |
|