Interpretation Conflict Affecting @hapi/content package, versions <6.0.2


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (17th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-HAPICONTENT-16881587
  • published27 May 2026
  • disclosed27 May 2026
  • creditYuki Shiroi

Introduced: 27 May 2026

NewCVE-2026-44974  (opens in a new tab)
CWE-436  (opens in a new tab)

How to fix?

Upgrade @hapi/content to version 6.0.2 or higher.

Overview

@hapi/content is a HTTP Content-* headers parsing

Affected versions of this package are vulnerable to Interpretation Conflict due to inconsistent handling of duplicate parameters in the Content.disposition and Content.type functions. An attacker can bypass upload filename allowlists or security filters by crafting requests with duplicate parameters that are interpreted differently by various components in the processing chain.

Workaround

This vulnerability can be mitigated by pre- or post-validating headers to detect and reject duplicates.

CVSS Base Scores

version 4.0
version 3.1