{"id":"CVE-2026-44974","aliases":["GHSA-36hh-x5p5-jgc8"],"url":"https://o3.security/vulnerability/CVE-2026-44974","summary":"Parameter smuggling in @hapi/content header parser allows upload-filter bypass via duplicate parameters","details":"@hapi/content provided HTTP Content-* headers parsing. Prior to 6.0.2, Content.disposition() retained the last occurrence of each duplicate parameter while Content.type() retained the first occurrence of duplicate charset and boundary parameters, creating a parameter-smuggling primitive when another component in the request-processing chain resolves duplicates the opposite way. This can allow an upload filename allowlist bypass in headers such as Content-Disposition: form-data; name=\"file\"; filename=\"safe.txt\"; filename=\"shell.php\". This issue is fixed in version 6.0.2.","published":"2026-07-17T20:11:44.250Z","modified":"2026-08-12T03:51:44.944947656Z","cvss":null,"epss":{"score":0.00344,"percentile":0.27442,"asOf":"2026-08-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@hapi/content","fixedVersion":"6.0.2"}],"fix":{"url":"https://github.com/hapijs/content/commit/3850079550c191d25e3643dc82a6d61144db8c2f","label":"hapijs/content@3850079"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44974.json"},{"type":"ADVISORY","url":"https://github.com/hapijs/content/security/advisories/GHSA-36hh-x5p5-jgc8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44974"},{"type":"FIX","url":"https://github.com/hapijs/content/commit/3850079550c191d25e3643dc82a6d61144db8c2f"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:44.944947656Z"}}