hapi
17 known vulnerabilities · 1 critical · 2 high
Denial of Service via malformed accept-encoding header in hapi
Incorrect handling of CORS preflight request headers in hapi
Uptime Kuma's Regular Expression in pushdeeer and whapi file Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
Malicious code in @trigo/trigo-hapijs (npm)
Malicious code in jewishapi (npm)
Malicious code in hapi-lint (npm)
Malicious code in @trigo/hapi-auth-signedlink (npm)
@hapi/content header parser has a parameter smuggling issue that allows upload-filter bypass via duplicate parameters
@hapi/wreck leaks sensitive `Proxy-Authorization` header across cross-hostname redirects
@hapi/content: Regular Expression Denial of Service (ReDoS) in HTTP header parsing
@hapi/inert has a static-file confinement bypass via sibling-prefix path
@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects