{"id":"CVE-2017-16111","details":"The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.","aliases":["GHSA-x6wp-rfwh-hcx7"],"modified":"2026-07-08T15:10:44.970951Z","published":"2018-06-07T02:29:02.677Z","references":[{"type":"ADVISORY","url":"https://nodesecurity.io/advisories/530"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hapijs/content","events":[{"introduced":"0"},{"last_affected":"e7f20cc6ff35b5c9787f3ebeebfe82a52f70a50d"}],"database_specific":{"cpe":"cpe:2.3:a:content_project:content:*:*:*:*:*:node.js:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"3.0.5"}],"source":"CPE_RANGE"}}],"versions":["v3.0.5","v3.0.4","v3.0.3","v3.0.2","v3.0.1","v3.0.0","v2.0.0","v1.0.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-16111.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}