Description
Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular expression denial of service when it is passed specially crafted input to parse. This causes the event loop to be blocked causing a denial of service condition.
Remediation
References
https://nodesecurity.io/advisories/526
Related Vulnerabilities
CVE-2018-11647 Vulnerability in npm package oauth2orize-fprm
CVE-2016-10538 Vulnerability in npm package cli
CVE-2022-41937 Vulnerability in maven package org.xwiki.platform:xwiki-platform-filter-ui
CVE-2019-0222 Vulnerability in maven package org.fusesource.mqtt-client:mqtt-client
CVE-2020-7647 Vulnerability in maven package org.jooby:jooby