Description
protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files.
Remediation
References
https://hackerone.com/reports/319576
Related Vulnerabilities
CVE-2022-25927 Vulnerability in maven package org.webjars.npm:ua-parser-js
CVE-2011-2481 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2021-41167 Vulnerability in npm package modern-async
CVE-2021-21346 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2021-43307 Vulnerability in maven package org.webjars.npm:semver-regex