VDB
Sign up
HIGH7.5

GHSA-jg4p-7fhp-p32p

@hapi/content: Regular Expression Denial of Service (ReDoS) in HTTP header parsing

Quick fix

GHSA-jg4p-7fhp-p32p — @hapi/content: upgrade to the fixed version with the command below.

npm install @hapi/content@6.0.1

Details

All versions of `@hapi/content` through 6.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via crafted HTTP header values. Three regular expressions used to parse `Content-Type` and `Content-Disposition` headers contain patterns susceptible to catastrophic backtracking. This has been fixed in v6.0.1.

### Impact

Denial of Service. An unauthenticated remote attacker can cause a Node.js process to become unresponsive by sending a single HTTP request with a maliciously crafted header value.

### Patches

Fixed by tightening all three regular expressions to eliminate backtracking.

### Workarounds

There are no known workarounds. Upgrade to the patched version.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@hapi/content
Introduced in: 0Fixed in: 6.0.1
Fixnpm install @hapi/content@6.0.1

References