CVE Database
/

CVE-2017-16111

Back to search

CVE-2017-16111

Published: Jun 7, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.

VendorProductVersions

HackerOne

content node module

affected
<=3.0.5

Weaknesses (CWE)

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now