OVERVIEW CVE-2026-35213 is a Regular Expression Denial of Service (ReDoS) vulnerability affecting @hapi/content, a Node.js library used for parsing HTTP Content-* headers. The flaw exists in all versions through 6.0.0 and stems from three regular expressions designed to parse Content-Type and Content-Disposition headers that are susceptible to catastrophic backtracking when processing specially crafted input. The vulnerability was resolved in version 6.0.1. SEVERITY This vulnerability carries a CVSS 3.1 score of 7.5 (HIGH), indicating significant risk with a network-based attack vector, low attack complexity, and no authentication requirements. The primary impact is availability disruption, as successful exploitation allows an unauthenticated attacker to cause denial of service conditions. The attack requires no user interaction or special privileges, making it accessible to remote adversaries. EXPLOITATION STATUS Currently, there is no evidence of active exploitation in the wild, as the vulnerability is not listed in the Known Exploited Vulnerabilities (KEV) database and remains inactive on threat intelligence hot lists. However, the relatively low EPSS score of 0.0036 suggests minimal real-world exploitation probability at present. Organizations should prioritize upgrading to version 6.0.1 to mitigate this availability risk, particularly for internet-facing systems relying on @hapi/content.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.0.1CPE matchmatch criteria | cpe:2.3:a:content_project:content:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.