Description
The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via crafted input in a parse call, aka a "regular expression denial of service (ReDoS)."
Remediation
References
http://www.openwall.com/lists/oss-security/2016/04/20/11
http://www.securityfocus.com/bid/96409
https://nodesecurity.io/advisories/48
Related Vulnerabilities
CVE-2022-24718 Vulnerability in npm package @finastra/ssr-pages
CVE-2019-1003061 Vulnerability in maven package org.jenkins-ci.plugins:jenkins-cloudformation-plugin
CVE-2021-37136 Vulnerability in maven package io.netty:netty-codec
CVE-2020-28452 Vulnerability in maven package com.softwaremill.akka-http-session:core_2.11
CVE-2020-27665 Vulnerability in npm package strapi-plugin-content-type-builder