Browse all 11 CVE security advisories affecting hapijs. AI-powered Chinese analysis, POCs, and references for each vulnerability.
This page aggregates security vulnerabilities reported for hapijs, a JavaScript framework for building APIs and applications. It collects known security flaws and their associated advisories within the tracked reporting period. Visitors can use this section to monitor the vendor's security posture, review specific product weakness patterns, and examine the historical vulnerability trends of the hapijs ecosystem.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-48022 | @hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects — wreck CWE-319 | 6.5 | Medium | 2026-07-17 |
| CVE-2026-44979 | @hapi/wreck : Sensitive `Proxy-Authorization` header leaked across cross-hostname redirects — wreck CWE-200 | - | - | 2026-07-17 |
This page lists every published CVE security advisory associated with hapijs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.