The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://nodesecurity.io/advisories/530 | third party advisory |