Description
This affects all versions of package ansi-html. If an attacker provides a malicious string, it will get stuck processing the input for an extremely long time.
Remediation
References
https://github.com/Tjatse/ansi-html/issues/19
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1567198
https://snyk.io/vuln/SNYK-JS-ANSIHTML-1296849
Related Vulnerabilities
CVE-2020-7602 Vulnerability in npm package node-prompt-here
CVE-2024-36401 Vulnerability in maven package org.geoserver:gs-wms
CVE-2021-4307 Vulnerability in maven package org.webjars.bower:baobab
CVE-2023-28444 Vulnerability in npm package angular-server-side-configuration
CVE-2022-25881 Vulnerability in maven package org.webjars.npm:http-cache-semantics