ZeroHour

CVE-2017-16111

CVSS 3.0
7.5 high
EPSS
1%p64
Published
()
Modified
Description

The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.

Vendors
content project
Products
content
Weakness
CWE-400
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.