Hapi · Hapi · CVE-2017-16013
Name of the Vulnerable Software and Affected Versions:
hapi versions 15.0.0 through 16.1.0
Description:
The issue occurs when hapi encounters a malformed `accept-encoding` header, which may cause it to crash or hang the client connection until the timeout period is reached. Affected versions of hapi will crash or lock the event loop when such a header is received.
Recommendations:
Update to version 16.1.1 or later.