{"id":"CVE-2017-16013","aliases":["GHSA-cqjg-whmm-8gv6"],"url":"https://o3.security/vulnerability/CVE-2017-16013","summary":"Denial of Service via malformed accept-encoding header in hapi","details":"hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught exception is thrown. This may cause hapi to crash or to hang the client connection until the timeout period is reached.","published":"2018-06-04T19:29:00.880Z","modified":"2026-07-08T12:06:16.270579Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"hapi","fixedVersion":"16.1.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/hapijs/hapi/issues/3466"},{"type":"ADVISORY","url":"https://nodesecurity.io/advisories/335"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:06:16.270579Z"}}