
Cloud Vulnerability DB
A community-led vulnerabilities database
A high-severity Denial of Service vulnerability was identified in the @hapi/ammo npm package (GHSA-gjph-xf5q-6mfq). The vulnerability affects versions prior to 3.1.2 and versions between 4.0.0 and 5.0.1. This security issue was discovered and reviewed on August 31, 2020, published to the GitHub Advisory Database on September 3, 2020, and last updated on January 9, 2023 (GitHub Advisory).
The vulnerability exists in the Range HTTP header parser of @hapi/ammo. When the header is set to an invalid value, the parser function throws a system error. Since the hapi framework is not designed to handle such exceptions, the error propagates up the stack. In the absence of an unhandled exception handler, this can lead to application termination (GitHub Advisory).
The exploitation of this vulnerability can result in a Denial of Service condition. If successfully exploited, attackers can force the application to shut down, disrupting service availability (GitHub Advisory).
The vulnerability can be triggered by sending an invalid Range HTTP header to affected applications. No specific exploit complexity details were provided in the advisory (GitHub Advisory).
Users are recommended to upgrade to the patched versions: either version 3.1.2 or 5.0.1, depending on their current version. These releases contain fixes for the vulnerability (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."