CVE-2017-16111

Publication date

2018-06-07 02:00:00

Family

hackerone

State

PUBLISHED

Description

The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.