GHSA-x6wp-rfwh-hcx7
GitHub Security Advisory
Regular Expression Denial of Service in content
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Affected versions of `content` are vulnerable to a regular expression denial of service when parsing malicious `Content-Type` and `Content-Disposition` headers.
## Recommendation
Update to version 3.0.6 or later.
Affected Packages
npm
content
Affected versions:
0
(fixed in 3.0.7)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 3, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.