PT-2026-43630 · Npm+3 · @Hapi/Content+2
CVE-2026-44974
·
Published
2026-05-27
·
Updated
2026-07-21
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
@rootio/hapi content versions prior to 6.0.2
Description
Inconsistent duplicate parameter resolution in the
Content.disposition() and Content.type() functions creates a parameter-smuggling primitive. While Content.disposition() retains the last occurrence of each parameter, Content.type() retains the first occurrence of charset and boundary. This discrepancy can be exploited when other components in the request-processing chain, such as a WAF or reverse proxy, resolve duplicates differently, potentially allowing an upload filename allowlist bypass.Recommendations
Update to version 6.0.2.
Pre or post validate headers to check for duplicates.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Hapi/Content
@Rootio/Hapi Content
Acontent