Description
Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a ua (aka User-Agent) value that only specifies the product and version.
Remediation
References
https://github.com/xCss/Valine/issues/366
Related Vulnerabilities
CVE-2021-32770 Vulnerability in npm package gatsby-source-wordpress
CVE-2020-8149 Vulnerability in npm package logkitty
CVE-2022-25231 Vulnerability in npm package node-opcua
CVE-2017-16134 Vulnerability in npm package http_static_simple
CVE-2021-32854 Vulnerability in maven package org.webjars.npm:textangular