CVE-2016-10543: Call Project Call

Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.

call is an HTTP router that is primarily used by the hapi framework. There exists a bug in call versions 2.0.1-3.0.1 that does not validate empty parameters, which could result in invalid input bypassing the route validation rules.

Affected products

Published 2018-05-31. Last modified 2026-06-17.