CVE-2017-16111 is a Regular Expression Denial of Service (ReDoS) vulnerability affecting the 'content' module, which is used by the hapijs framework to parse HTTP Content-* headers. Specifically crafted Content-Type or Content-Disposition headers can trigger this vulnerability. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating a severe impact with a network-based attack vector and low attack complexity, leading to high availability impact (denial of service). There is no confidentiality or integrity impact. There is currently no evidence of active exploitation, nor are there any public exploit modules available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.0.5CPE matchmatch criteria | cpe:2.3:a:content_project:content:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.