Vulnerability DatabaseGHSA-gjph-xf5q-6mfq

GHSA-gjph-xf5q-6mfq
JavaScript vulnerability analysis and mitigation

Overview

A high-severity Denial of Service vulnerability was identified in the @hapi/ammo npm package (GHSA-gjph-xf5q-6mfq). The vulnerability affects versions prior to 3.1.2 and versions between 4.0.0 and 5.0.1. This security issue was discovered and reviewed on August 31, 2020, published to the GitHub Advisory Database on September 3, 2020, and last updated on January 9, 2023 (GitHub Advisory).

Technical details

The vulnerability exists in the Range HTTP header parser of @hapi/ammo. When the header is set to an invalid value, the parser function throws a system error. Since the hapi framework is not designed to handle such exceptions, the error propagates up the stack. In the absence of an unhandled exception handler, this can lead to application termination (GitHub Advisory).

Impact

The exploitation of this vulnerability can result in a Denial of Service condition. If successfully exploited, attackers can force the application to shut down, disrupting service availability (GitHub Advisory).

Exploitability

The vulnerability can be triggered by sending an invalid Range HTTP header to affected applications. No specific exploit complexity details were provided in the advisory (GitHub Advisory).

Mitigation and workarounds

Users are recommended to upgrade to the patched versions: either version 3.1.2 or 5.0.1, depending on their current version. These releases contain fixes for the vulnerability (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-63376HIGH8.2
  • JavaScript logoJavaScript
  • trigger-dev
NoYesSep 03, 2026
GHSA-7q9c-hpx7-9cwmHIGH7.5
  • JavaScript logoJavaScript
  • @typespec/spector
NoYesSep 04, 2026
CVE-2026-77465HIGH7.5
  • JavaScript logoJavaScript
  • cockpit-image-builder.src
NoYesSep 03, 2026
CVE-2026-71429MEDIUM6.2
  • JavaScript logoJavaScript
  • stream-json
NoYesSep 03, 2026
GHSA-6hxq-p678-4hr2LOW2
  • JavaScript logoJavaScript
  • @simplewebauthn/server
NoYesSep 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management