Executive brief
@hapi/ammo is a popular Node.js library used to parse HTTP range requests in hapi-based web applications. An attacker can crash the application by sending an HTTP request with a malformed Range header, causing the service to become unavailable until it is restarted.
Technical details
The vulnerability is a Denial of Service (DoS) triggered by improper error handling in the Range HTTP header parser within @hapi/ammo. When the parser encounters an invalid Range header value, it throws an unhandled exception that propagates up the stack instead of being caught gracefully. Since hapi framework components are not designed to handle exceptions from this parser, an unauthenticated attacker can send a crafted HTTP request with a malformed Range header to cause the application process to crash. Versions prior to 3.1.2 (for the 0–3.x branch) and prior to 5.0.1 (for the 4.x–5.x branch) are affected. The fix is available in versions 3.1.2 and 5.0.1.
Affected products
- hapi @hapi/ammo < 3.1.2 and 4.0.0–< 5.0.1
Timeline
- 2020-09-03: disclosed
- 2020-09-03: patched: versions 3.1.2 and 5.0.1 released