Hawk before 3.1.3 and 4.x before 4.1.1 allow remote attackers to cause a denial of service (CPU consumption or partial outage) via a long (1) header or (2) URI that is matched against an improper regular expression.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "3.1.2"
},
{
"introduced": "0"
},
{
"last_affected": "4.1.0"
}
]
}