Description
Versions of content are vulnerable to Denial of Service. The Content-Encoding HTTP header parser has a vulnerability which will cause the function to throw a system error if the header contains some invalid values.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 4.0.6
References
Related Issues
- Regular Expression Denial of Service in clean-css - Vulnerability
- Regular Expression Denial of Service in millisecond - Vulnerability
- Denial of Service in url-relative - Vulnerability
- string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS) - CVE-2025-45143
You might also like:
- Tags:
- npm
- content
Anything's wrong? Let us know Last updated on September 29, 2025


