{"id":"CVE-2026-44974","aliases":["GHSA-36hh-x5p5-jgc8"],"url":"https://o3.security/vulnerability/CVE-2026-44974","summary":"Parameter smuggling in @hapi/content header parser allows upload-filter bypass via duplicate parameters","details":"### Impact\nThe two parsers resolved duplicates inconsistently and silently:\n- `Content.disposition()` retained the last occurrence of each parameter.\n- `Content.type()` retained the first occurrence of charset and boundary.\n\nEither behavior creates a parameter-smuggling primitive when another component in the request-processing chain (a WAF, reverse proxy, security filter, or alternate parser) resolves duplicates the opposite way. The primary attack vector is upload filename allowlist bypass:\n\n`Content-Disposition: form-data; name=\"file\"; filename=\"safe.txt\"; filename=\"shell.php\"`\n\n### Patches\nThe issue has been patched in 6.0.2.\n\n### Workarounds\nPre or post validate headers looking for duplicates.\n\n### Resources\n- [RFC 6266 §4.1 — Content-Disposition syntax](https://www.rfc-editor.org/rfc/rfc6266#section-4.1)\n- [RFC 7231 §3.1.1.1 — Content-Type syntax](https://www.rfc-editor.org/rfc/rfc7231#section-3.1.1.1)\n- [RFC 7230 §3.2.6 — token character set](https://www.rfc-editor.org/rfc/rfc7230#section-3.2.6)","published":"2026-07-17T20:11:44.250Z","modified":"2026-08-12T03:51:44.944947656Z","cvss":null,"epss":{"score":0.00344,"percentile":0.27442,"asOf":"2026-08-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@hapi/content","fixedVersion":"6.0.2"}],"fix":{"url":"https://github.com/hapijs/content/commit/3850079550c191d25e3643dc82a6d61144db8c2f","label":"hapijs/content@3850079"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44974.json"},{"type":"ADVISORY","url":"https://github.com/hapijs/content/security/advisories/GHSA-36hh-x5p5-jgc8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44974"},{"type":"FIX","url":"https://github.com/hapijs/content/commit/3850079550c191d25e3643dc82a6d61144db8c2f"},{"type":"PACKAGE","url":"https://github.com/hapijs/content"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:44.944947656Z"}}