Security Advisory

CVE-2017-16111

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-06-07 02:00:00
Last updated 2024-09-16 20:37:31
Assigner hackerone
CVSS score not scored
State PUBLISHED

Description

The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.