Skip to content

Update dependency hawk to v9 [SECURITY] - #19

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-hawk-vulnerability
Open

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-hawk-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 3, 2026

Copy link
Copy Markdown

This PR contains the following updates:

Package Change Age Confidence
hawk ~3.1.0 → ~9.0.0 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Uncontrolled Resource Consumption in Hawk

CVE-2022-29167 / GHSA-44pw-h2cw-w3vq

More information

Details

Hawk is an HTTP authentication scheme providing mechanisms for making authenticated HTTP requests with partial cryptographic verification of the request and response, covering the HTTP method, request URI, host, and optionally the request payload. Hawk used a regular expression to parse Host HTTP header (Hawk.utils.parseHost()), which was subject to regular expression DoS attack - meaning each added character in the attacker's input increases the computation time exponentially. parseHost() was patched in 9.0.1 to use built-in URL class to parse hostname instead.Hawk.authenticate() accepts options argument. If that contains host and port, those would be used instead of a call to utils.parseHost().

Severity

  • CVSS Score: 7.4 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

mozilla/hawk (hawk)

v9.0.2

Compare Source

Security fixes.

This is going to be the final release of this library, see #​293 (comment)

What's Changed

Full Changelog: mozilla/hawk@v9.0.1...v9.0.2

v9.0.1

Compare Source

Fix host parsing.

Full Changelog: mozilla/hawk@v9.0.0...v9.0.1

v9.0.0

Compare Source

This release drops the requirement for @​hapi/sntp, which was used for time synchronization (#​277).

Note that @​hapi/sntp is no longer maintained. The API lists a workaround for those needing this functionality.

v8.0.1

Compare Source

No code has changed since 8.0.0. This release is to update the README and links on npmjs.org.

v8.0.0

Compare Source

Breaking Changes:

  • drop support for Hapi 18
  • drop support for Node < 12

Changes

v7.1.2

Compare Source

Changes

v7.1.1

Compare Source

Changes

v7.1.0

Compare Source

Breaking change: remove browser exports

All changes

v7.0.10

Compare Source

Changes

v7.0.9

Compare Source

Changes

v7.0.7

Compare Source

Changes

v7.0.6

Compare Source

Changes

v7.0.5

Compare Source

Changes

v7.0.4

Compare Source

Changes

v7.0.3

Compare Source

Changes

v7.0.2

Compare Source

Changes

v7.0.1

Compare Source

changes

v7.0.0

Compare Source

Breaking changes:

v6.0.2

Compare Source

v6.0.1

Compare Source

v6.0.0

Compare Source

v5.1.2

Compare Source

v5.1.1

Compare Source

v5.1.0

Compare Source

v5.0.1

Compare Source

v5.0.0

Compare Source

v4.1.2

Compare Source

v4.1.1

Compare Source

v4.1.0

Compare Source

v4.0.1

Compare Source

v4.0.0

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@mergify

mergify Bot commented Oct 3, 2026

Copy link
Copy Markdown

Tick the box to add this pull request to the merge queue (same as @mergifyio queue).

  • Queue this pull request

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants