GHSA-jg4p-7fhp-p32p
@hapi/content: Regular Expression Denial of Service (ReDoS) in HTTP header parsing
Quick fix
GHSA-jg4p-7fhp-p32p — @hapi/content: upgrade to the fixed version with the command below.
npm install @hapi/content@6.0.1Details
All versions of `@hapi/content` through 6.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via crafted HTTP header values. Three regular expressions used to parse `Content-Type` and `Content-Disposition` headers contain patterns susceptible to catastrophic backtracking. This has been fixed in v6.0.1.
### Impact
Denial of Service. An unauthenticated remote attacker can cause a Node.js process to become unresponsive by sending a single HTTP request with a maliciously crafted header value.
### Patches
Fixed by tightening all three regular expressions to eliminate backtracking.
### Workarounds
There are no known workarounds. Upgrade to the patched version.
Are you affected?
Enter the version of the package you're using.