PT-2026-43630 · Npm+3 · @Hapi/Content+2

CVE-2026-44974

·

Published

2026-05-27

·

Updated

2026-07-21

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions @rootio/hapi content versions prior to 6.0.2
Description Inconsistent duplicate parameter resolution in the Content.disposition() and Content.type() functions creates a parameter-smuggling primitive. While Content.disposition() retains the last occurrence of each parameter, Content.type() retains the first occurrence of charset and boundary. This discrepancy can be exploited when other components in the request-processing chain, such as a WAF or reverse proxy, resolve duplicates differently, potentially allowing an upload filename allowlist bypass.
Recommendations Update to version 6.0.2. Pre or post validate headers to check for duplicates.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44974
GHSA-36HH-X5P5-JGC8

Affected Products

@Hapi/Content
@Rootio/Hapi Content
Acontent