CVE-2017-16005: Joyent HTTP-Signature
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to header forgery. Thus, if an attacker can intercept a request, he can swap header names and change the meaning of the request without changing the signature.
Affected products
- Joyent HTTP-Signature: up to and including 0.9.11
Published 2018-06-04. Last modified 2026-06-17.