VDB
Sign up
HIGH7.5

GHSA-x6wp-rfwh-hcx7

Regular Expression Denial of Service in content

Quick fix

GHSA-x6wp-rfwh-hcx7 — content: upgrade to the fixed version with the command below.

npm install content@3.0.7

Details

Affected versions of `content` are vulnerable to a regular expression denial of service when parsing malicious `Content-Type` and `Content-Disposition` headers.

## Recommendation

Update to version 3.0.6 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/content
Introduced in: 0Fixed in: 3.0.7
Fixnpm install content@3.0.7

References