Description
sshpk is vulnerable to ReDoS when parsing crafted invalid public keys.
Remediation
References
https://hackerone.com/reports/319593
Related Vulnerabilities
CVE-2017-16180 Vulnerability in npm package serverabc
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http-core_2.13
CVE-2021-25642 Vulnerability in maven package org.apache.hadoop:hadoop-yarn-server-resourcemanager
CVE-2020-28469 Vulnerability in maven package org.webjars.npm:glob-parent
CVE-2023-26487 Vulnerability in maven package org.webjars.npm:vega