Description
This affects all versions of package ansi-html. If an attacker provides a malicious string, it will get stuck processing the input for an extremely long time.
Remediation
References
https://github.com/Tjatse/ansi-html/issues/19
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1567198
https://snyk.io/vuln/SNYK-JS-ANSIHTML-1296849
Related Vulnerabilities
CVE-2021-42227 Vulnerability in npm package kindeditor
CVE-2020-13933 Vulnerability in maven package org.apache.shiro:shiro-web
CVE-2021-41269 Vulnerability in maven package com.cronutils:cron-utils
CVE-2022-39230 Vulnerability in npm package fhir-works-on-aws-authz-smart
CVE-2015-1169 Vulnerability in maven package org.jasig.cas:cas-server-support-ldap