AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-29167

HIGH · CVSS 7.4 EPSS 1.09% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-05-05 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2022-29167
Severity
HIGH
CVSS
7.4
EPSS
1.09%

Original NVD Description

Hawk is an HTTP authentication scheme providing mechanisms for making authenticated HTTP requests with partial cryptographic verification of the request and response, covering the HTTP method, request URI, host, and optionally the request payload. Hawk used a regular expression to parse `Host` HTTP header (`Hawk.utils.parseHost()`), which was subject to regular expression DoS attack - meaning each added character in the attacker's input increases the computation time exponentially. `parseHost()` was patched in `9.0.1` to use built-in `URL` class to parse hostname instead. `Hawk.authenticate()` accepts `options` argument. If that contains `host` and `port`, those would be used instead of a call to `utils.parseHost()`.

Related CVEs

Other vulnerabilities affecting the same vendor(s)