@hapi/content
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @hapi/contentpage 1 of 1
- CVE-2026-35213HIGHCVSS 8.7EG 8.7✓ Fixed in 6.0.12026-04-06
@hapi/content provided HTTP Content-* headers parsing. All versions of @hapi/content through 6.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via crafted HTTP header values. Three regular expressions used to parse Conte…
- CVE-2026-44974HIGHCVSS 7.7EG 7.7✓ Fixed in 6.0.22026-05-27
@hapi/content provided HTTP Content-* headers parsing. Prior to 6.0.2, Content.disposition() retained the last occurrence of each duplicate parameter while Content.type() retained the first occurrence of duplicate charset and boundary para…
Check whether @hapi/content is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @hapi/content CVEs against the assets you own.
Start Free Scan →