Executive brief
ammo is an HTTP utility library used by the hapi web framework. A vulnerability in the Range HTTP header parser causes the library to throw an unhandled exception when given malformed input, crashing the application and denying service to legitimate users. An attacker can exploit this by sending requests with invalid Range headers, causing the entire service to shut down.
Technical details
The vulnerability is an unhandled exception in the Range HTTP header parser component of ammo. When the Range header is set to an invalid value, the parser throws a system error. Because hapi does not expect the function to throw exceptions, the error propagates uncaught up the call stack. If the application lacks a top-level unhandled exception handler, this causes the Node.js process to terminate, resulting in a denial of service. The attack vector is network-accessible (via HTTP requests), requires no authentication, and affects all versions of the original ammo package. The package is now deprecated in favor of @hapi/ammo.
Affected products
- npm ammo all
Timeline
- 2020-09-03: disclosed