Junglewise Threat Intelligence

CVE-2016-2515: hawk Regular Expression Denial of Service

CVE-2016-2515 · Severity: low · CVSS 3 · Published 2018-07-31

Executive brief

hawk is a Node.js authentication library used to sign and verify HTTP requests. A regular expression denial of service (ReDoS) vulnerability allows attackers to crash or hang services by crafting requests with excessively long headers or URIs, potentially causing service unavailability.

Technical details

The vulnerability is a regular expression denial of service (ReDoS, CWE-1333) caused by insufficiently bounded regular expressions processing HTTP headers and URIs. Vulnerable versions are hawk prior to 3.1.3 and 4.x prior to 4.1.1. The attack requires no authentication and can be triggered remotely by sending HTTP requests with excessively long headers or URIs, causing the regex engine to enter catastrophic backtracking and consuming CPU resources. An attacker can trigger a denial of service against any service using the vulnerable library. Patches are available in versions 3.1.3 and 4.1.1 or later.

Affected products

  • hawk hawk prior to 3.1.3 and 4.x prior to 4.1.1

Timeline

  • 2016-02-20: disclosed
  • 2018-07-31: patched

References