High severityGHSA Advisory· Published Jul 17, 2026· Updated Jul 23, 2026
CVE-2026-44974
CVE-2026-44974
Description
@hapi/content provided HTTP Content-* headers parsing. Prior to 6.0.2, Content.disposition() retained the last occurrence of each duplicate parameter while Content.type() retained the first occurrence of duplicate charset and boundary parameters, creating a parameter-smuggling primitive when another component in the request-processing chain resolves duplicates the opposite way. This can allow an upload filename allowlist bypass in headers such as Content-Disposition: form-data; name="file"; filename="safe.txt"; filename="shell.php". This issue is fixed in version 6.0.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@hapi/contentnpm | < 6.0.2 | 6.0.2 |
Affected products
13- Range: < 6.0.2
- osv-coords12 versionspkg:apk/chainguard/kibana-8.19pkg:apk/chainguard/kibana-8.19-bitnamipkg:apk/chainguard/kibana-8.19-iamguardedpkg:apk/chainguard/kibana-9.3pkg:apk/chainguard/kibana-9.3-iamguardedpkg:apk/chainguard/kibana-9.4pkg:apk/chainguard/kibana-9.4-iamguardedpkg:apk/chainguard/opensearch-dashboards-3pkg:apk/chainguard/opensearch-dashboards-3-fipspkg:apk/chainguard/wazuh-dashboardpkg:apk/chainguard/wazuh-dashboard-fipspkg:apk/wolfi/opensearch-dashboards-3
< 8.19.16-r3+ 11 more
- (no CPE)range: < 8.19.16-r3
- (no CPE)range: < 8.19.16-r3
- (no CPE)range: < 8.19.16-r3
- (no CPE)range: < 9.3.5-r0
- (no CPE)range: < 9.3.5-r0
- (no CPE)range: < 9.4.2-r0
- (no CPE)range: < 9.4.2-r0
- (no CPE)range: < 3.7.0-r2
- (no CPE)range: < 3.7.0-r2
- (no CPE)range: < 4.14.5-r3
- (no CPE)range: < 4.14.5-r3
- (no CPE)range: < 3.7.0-r2
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.