[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#1025414: bullseye-pu: package node-hawk/8.0.1+dfsg-2+deb11u1



Control: tags -1 + confirmed

On Sun, 2022-12-04 at 11:42 +0100, Yadd wrote:
> node-hawk used a regular expression to parse `Host` HTTP header
> (`Hawk.utils.parseHost()`), which was subject to regular expression
> DoS attack
> (CVE-2022-29167).
> 

Please go ahead.

Regards,

Adam


Reply to: