What the vulnerability does

01Description

The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.

Key dates

02Disclosure timeline

June 7, 2018 CVE published
September 16, 2024 Record updated