{"id":"GHSA-36hh-x5p5-jgc8","summary":"@hapi/content header parser has a parameter smuggling issue that allows upload-filter bypass via duplicate parameters","details":"### Impact\nThe two parsers resolved duplicates inconsistently and silently:\n- `Content.disposition()` retained the last occurrence of each parameter.\n- `Content.type()` retained the first occurrence of charset and boundary.\n\nEither behavior creates a parameter-smuggling primitive when another component in the request-processing chain (a WAF, reverse proxy, security filter, or alternate parser) resolves duplicates the opposite way. The primary attack vector is upload filename allowlist bypass:\n\n`Content-Disposition: form-data; name=\"file\"; filename=\"safe.txt\"; filename=\"shell.php\"`\n\n### Patches\nThe issue has been patched in 6.0.2.\n\n### Workarounds\nPre or post validate headers looking for duplicates.\n\n### Resources\n- [RFC 6266 §4.1 — Content-Disposition syntax](https://www.rfc-editor.org/rfc/rfc6266#section-4.1)\n- [RFC 7231 §3.1.1.1 — Content-Type syntax](https://www.rfc-editor.org/rfc/rfc7231#section-3.1.1.1)\n- [RFC 7230 §3.2.6 — token character set](https://www.rfc-editor.org/rfc/rfc7230#section-3.2.6)","aliases":["CVE-2026-44974"],"modified":"2026-08-24T00:36:43.799765284Z","published":"2026-05-27T00:37:20Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-436"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-05-27T00:37:20Z"},"references":[{"type":"WEB","url":"https://github.com/hapijs/content/security/advisories/GHSA-36hh-x5p5-jgc8"},{"type":"WEB","url":"https://github.com/hapijs/content/commit/3850079550c191d25e3643dc82a6d61144db8c2f"},{"type":"PACKAGE","url":"https://github.com/hapijs/content"}],"affected":[{"package":{"name":"@hapi/content","ecosystem":"npm","purl":"pkg:npm/%40hapi/content"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-36hh-x5p5-jgc8/GHSA-36hh-x5p5-jgc8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N"}]}