hapijs
OSS Librariesoss-project
Latest CVEs
The 15 most recently published vulnerabilities affecting hapijs.
- CVE-2026-92599Joi before 17.13.7 and 18.2.6 ReDoS via isoDate7.5
- CVE-2026-90771joi before 17.13.8 and 18.2.9 Prototype Pollution via messages3.7
- CVE-2026-84368joi: Prototype pollution via a `__proto__` language key in custom messages3.7
- CVE-2026-84367joi: object().rename() with a template target can set the validated object's prototype3.7
- CVE-2026-48049@hapi/inert: Static-file confinement bypass via sibling-prefix path5.3
- CVE-2026-48022@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects6.5
- CVE-2026-44979@hapi/wreck : Sensitive `Proxy-Authorization` header leaked across cross-hostname redirects
- CVE-2026-44974Parameter smuggling in @hapi/content header parser allows upload-filter bypass via duplicate parameters
- CVE-2026-48038joi: Uncaught RangeError on deeply nested input through recursive `link()` schemas5.3
- CVE-2026-35213Regular Expression Denial of Service (ReDoS) in @hapi/content HTTP header parsing7.5
- CVE-2023-25166Regular Expression Denial of Service (ReDoS) Vulnerability5.5
- CVE-2020-36604hoek before 8.5.1 and 9.x before 9.0.3 allows prototype poisoning in the clone function.8.1
- CVE-2017-16025Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vulnerability via an invalid Cookie header. This is only pr...5.9
- CVE-2017-16013hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught exception is thrown. This may cause hapi to crash or to h...7.5
- CVE-2015-9236Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent headers and at worst allowed cross-origin activities that were expected t...5.3