Hapijs develops a modestly represented framework and utility library ecosystem for Node.js web applications, centered on the Hapi web framework alongside supporting packages such as Hoek and Nes. The recurring vulnerability patterns reflect the authentication, access control, and input-handling demands of a web application platform, spanning weakness classes including uncontrolled resource consumption, improper access control, improper input validation, and exposure of sensitive information. Current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hapijs over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-3728HIGH hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' and 'applyToDefaults' functions, which a | Mar 30, 2018 | 8.8 | 29 | NO | NO |
CVE-2020-36604HIGH hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function. | Sep 23, 2022 | 8.1 | 27 | NO | NO |
CVE-2017-16013HIGH hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught exception is thrown. This may cause hapi | Jun 4, 2018 | 7.5 | 23 | NO | NO |
CVE-2015-9241HIGH Certain input passed into the If-Modified-Since or Last-Modified headers will cause an 'illegal access' exception to be raised. Instead of sending a HTTP 500 error back to the send | May 29, 2018 | 7.5 | 21 | NO | NO |
CVE-2017-16025MEDIUM Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vulnerability via an invalid Cookie header | Jun 4, 2018 | 5.9 | 19 | NO | NO |
CVE-2015-9243MEDIUM When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher level config included security restrictions | May 29, 2018 | 5.9 | 18 | NO | NO |
CVE-2015-9236MEDIUM Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent headers and at worst allowed cross-origin activities tha | May 31, 2018 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hapijs.
Media articles that mention a CVE ID that affects a product developed by Hapijs — matched by CVE ID, not by vendor name.