Medium severity5.3NVD Advisory· Published May 31, 2018· Updated Jun 17, 2026
CVE-2015-9236
CVE-2015-9236
Description
Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent headers and at worst allowed cross-origin activities that were expected to be forbidden. If the connection has CORS enabled but one route has it off, and the route is not GET, the OPTIONS prefetch request will return the default CORS headers and then the actual request will go through and return no CORS headers. This defeats the purpose of turning CORS on the route.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
hapinpm | < 11.0.0 | 11.0.0 |
Affected products
3- Range: <11.0.0
Patches
Vulnerability mechanics
References
6- github.com/hapijs/hapi/issues/2840nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-vwrf-r5r4-7775ghsaADVISORY
- github.com/hapijs/hapi/issues/2850nvdRelease NotesThird Party AdvisoryWEB
- nodesecurity.io/advisories/45nvdThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2015-9236ghsaADVISORY
- www.npmjs.com/advisories/45ghsaWEB
News mentions
0No linked articles in our index yet.