Description
The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.
Remediation
References
https://nodesecurity.io/advisories/530
Related Vulnerabilities
CVE-2017-2607 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-2228 Vulnerability in maven package org.jenkins-ci.plugins:gitlab-oauth
CVE-2018-8811 Vulnerability in maven package org.opencms:opencms-core
CVE-2021-23497 Vulnerability in npm package @strikeentco/set
CVE-2018-18853 Vulnerability in maven package io.spray:spray-json_2.12