{"id":"CVE-2017-16111","aliases":["GHSA-x6wp-rfwh-hcx7"],"url":"https://o3.security/vulnerability/CVE-2017-16111","summary":"Regular Expression Denial of Service in content","details":"The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.","published":"2018-06-07T02:29:02.677Z","modified":"2026-08-07T15:18:49.049393Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"content","fixedVersion":"3.0.7"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nodesecurity.io/advisories/530"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:18:49.049393Z"}}