Hawk before 3.1.3 and 4.x before 4.1.1 allow remote attackers to cause a denial of service (CPU consumption or partial outage) via a long (1) header or (2) URI that is matched against an improper regular expression.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Hawk | Hawk_project | 3.1.2 (including) | 3.1.2 (including) |
Hawk | Hawk_project | 4.1.0 (including) | 4.1.0 (including) |