Junglewise Threat Intelligence

@hapi/accept denial of service in Accept-Encoding parser

Severity: info · Published 2020-09-03

Vendors: Hapi.

Executive brief

@hapi/accept is a Node.js library that parses HTTP Accept headers in web applications. A vulnerability in its Accept-Encoding header parser allows an attacker to send specially crafted HTTP requests that crash the application, resulting in service unavailability. No authentication or user interaction is required to exploit this vulnerability.

Technical details

The vulnerability is a denial of service (DoS) caused by improper error handling in the Accept-Encoding HTTP header parser. When the parser encounters certain invalid header values, it throws a system error instead of an application error. The hapi framework rethrows system errors up the stack, and if no unhandled exception handler is configured, the application process terminates. An attacker can exploit this by sending a malicious Accept-Encoding header in any HTTP request to trigger the parsing error. The vulnerability affects versions 3.2.0–3.2.3 and 4.0.0–5.0.0; fixes are available in versions 3.2.4 and 5.0.1.

Affected products

  • Hapi @hapi/accept 3.2.0–3.2.3, 4.0.0–5.0.0

Timeline

  • 2020-09-03: disclosed

References