Description
The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.
Remediation
References
https://nodesecurity.io/advisories/530
Related Vulnerabilities
CVE-2020-5251 Vulnerability in npm package parse-server
CVE-2014-6393 Vulnerability in maven package org.webjars.npm:express
CVE-2017-5664 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2022-1466 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2018-20677 Vulnerability in maven package org.webjars.npm:bootstrap-sass