I'm wondering if Hiawatha relies on Bash and, therefore, if a default configuration exposes a vulnerable bash.
I tried this test against my servers and came back negative, though I have not upgraded bash yet:
http://shellshock.brandonpotter.com/Some details about the bug here.
http://www.troyhunt.com/2014/09/everything-you-need-to-know-about.html