Medium severity5.9NVD Advisory· Published Jun 4, 2018· Updated Jun 17, 2026
CVE-2017-16025
CVE-2017-16025
Description
Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vulnerability via an invalid Cookie header. This is only present when websocket authentication is set to cookie. Submitting an invalid cookie on the websocket upgrade request will cause the node process to error out.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nesnpm | < 6.4.1 | 6.4.1 |
Affected products
3- Range: <=6.4.0
Patches
Vulnerability mechanics
References
6- github.com/hapijs/nes/commit/249ba1755ed6977fbc208463c87364bf884ad655nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-3pwh-5mmc-mwrxghsaADVISORY
- github.com/hapijs/nes/issues/171nvdThird Party AdvisoryWEB
- nodesecurity.io/advisories/331nvdThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2017-16025ghsaADVISORY
- www.npmjs.com/advisories/331ghsaWEB
News mentions
0No linked articles in our index yet.