Description
Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular expression denial of service when it is passed specially crafted input to parse. This causes the event loop to be blocked causing a denial of service condition.
Remediation
References
https://nodesecurity.io/advisories/526
Related Vulnerabilities
CVE-2022-36083 Vulnerability in npm package jose-node-esm-runtime
CVE-2022-25760 Vulnerability in npm package accesslog
CVE-2022-31142 Vulnerability in npm package @fastify/bearer-auth
CVE-2020-2176 Vulnerability in maven package it.infuse.jenkins:usemango-runner
CVE-2022-24718 Vulnerability in npm package @finastra/ssr-pages