Junglewise Threat Intelligence

CVE-2017-16013: hapi denial of service via malformed accept-encoding header

CVE-2017-16013 · Severity: low · CVSS 3 · Published 2018-10-09

Technologies: hapi (npm). Vendors: npm, Hapi.

Executive brief

hapi is a popular Node.js web application framework. When a malformed accept-encoding HTTP header is received, the framework crashes or enters an infinite loop, causing the web application to become unresponsive and potentially timeout across multiple client connections.

Technical details

hapi versions 15.0.0 through 16.1.0 improperly handle malformed accept-encoding headers, resulting in a denial of service. The vulnerability exists in the compression module (lib/compression.js) where the framework fails to validate the header format before attempting to use it as an encoding type. When a non-conformant header is received, the code enters an error state and never sends a response to the client, leaving connections hanging. This is triggered via a network-accessible HTTP request and requires no authentication or user interaction. An attacker can craft and send malicious accept-encoding headers to cause the server to hang or crash, disrupting service availability. The issue was fixed in version 16.1.1.

Affected products

  • hapi hapi 15.0.0 to 16.1.0

Timeline

  • 2017-03-31: disclosed: Issue reported on GitHub
  • 2017: patched: Fixed in version 16.1.1
  • 2018-10-09: advisory: GHSA advisory published

References

Related threats