Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35213

27
FAUCET Score

OVERVIEW CVE-2026-35213 is a Regular Expression Denial of Service (ReDoS) vulnerability affecting @hapi/content, a Node.js library used for parsing HTTP Content-* headers. The flaw exists in all versions through 6.0.0 and stems from three regular expressions designed to parse Content-Type and Content-Disposition headers that are susceptible to catastrophic backtracking when processing specially crafted input. The vulnerability was resolved in version 6.0.1. SEVERITY This vulnerability carries a CVSS 3.1 score of 7.5 (HIGH), indicating significant risk with a network-based attack vector, low attack complexity, and no authentication requirements. The primary impact is availability disruption, as successful exploitation allows an unauthenticated attacker to cause denial of service conditions. The attack requires no user interaction or special privileges, making it accessible to remote adversaries. EXPLOITATION STATUS Currently, there is no evidence of active exploitation in the wild, as the vulnerability is not listed in the Known Exploited Vulnerabilities (KEV) database and remains inactive on threat intelligence hot lists. However, the relatively low EPSS score of 0.0036 suggests minimal real-world exploitation probability at present. Organizations should prioritize upgrading to version 6.0.1 to mitigate this availability risk, particularly for internet-facing systems relying on @hapi/content.

Impacted Technologies

VendorProductVersion(s)CPE
< 6.0.1CPE matchmatch criteria
cpe:2.3:a:content_project:content:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

8.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.41%
Probability of exploitation in next 30 days
EPSS Percentile
33.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0041 is in the 13th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: @hapi/contentFixed in: 6.0.1

Vendor Advisories (1)

npmGHSA-jg4p-7fhp-p32phigh

@hapi/content: Regular Expression Denial of Service (ReDoS) in HTTP header parsing

Apr 4, 2026

References

github.com / hapijs/content/pull/38
Issue TrackingPatch
github.com / hapijs/content/security/advisories/GHSA-jg4p-7fhp-p32p
Vendor Advisory