Description
sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.
Remediation
References
https://hackerone.com/reports/319593
Related Vulnerabilities
CVE-2020-8136 Vulnerability in npm package fastify-multipart
CVE-2020-26291 Vulnerability in maven package org.webjars.npm:urijs
CVE-2020-7632 Vulnerability in npm package node-mpv
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-beam
CVE-2014-10065 Vulnerability in maven package org.webjars:remarkable